Skip to content

Defendnot

Defendnot is a tool abused to disable Microsoft Defender on Windows by registering a fake antivirus product with Windows Security Center (WSC), including via the IWscAvStatus interface, causing Defender to automatically turn itself off to avoid conflicts.

Profile source: Mallory opens in a new tab

Defendnot

Family profile

Defendnot is a tool abused to disable Microsoft Defender on Windows by registering a fake antivirus product with Windows Security Center (WSC), including via the IWscAvStatus interface, causing Defender to automatically turn itself off to avoid conflicts. The content describes it as a research tool originally designed to demonstrate weaknesses in the Windows Security Center trust model, later repurposed operationally in malware campaigns.

Behavior described in the content includes process injection into a trusted Microsoft-signed process such as Taskmgr.exe, interaction with undocumented or vendor-oriented WSC APIs, and fraudulent antivirus registration. In some reporting, Defendnot components were deployed as defendnot.dll and defendnot-loader.exe under %PROGRAMDATA%, with injection telemetry potentially visible via Sysmon Event IDs 7, 8, and 10 and process creation via Event ID 4688. Optional persistence artifacts mentioned alongside its use include autorun registry entries and scheduled task creation or modification.

Defendnot appears in a multi-stage phishing campaign primarily targeting users and organizations in Russia. In that campaign, victims were lured via compressed archives containing business/accounting-themed decoys and malicious LNK files that launched PowerShell to retrieve additional stages from GitHub. After privilege escalation attempts through repeated UAC prompts, the malware disabled Defender through PowerShell configuration changes, exclusions, and Defendnot deployment, then proceeded with reconnaissance, screenshot capture, Amnesia RAT installation, and Hakuna Matata-derived ransomware/WinLocker deployment. Associated infrastructure and tooling mentioned in the content include GitHub and Dropbox for payload hosting and Telegram Bot API for operator notification and exfiltration.

High-confidence indicators and artifacts directly mentioned in the content include Defendnot registering a fake AV in Windows Security Center, possible visible registration of a fake antivirus product in the GUI, Defender state changes, deployment paths such as %PROGRAMDATA%\defendnot.dll and %PROGRAMDATA%\defendnot-loader.exe, and abuse of Taskmgr.exe as an injection target. The primary purpose consistently described is defense evasion through neutralization of Microsoft Defender rather than direct exploitation of Defender itself.

MITRE ATT&CK

Defendnot in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.