logo

Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds With Automatic Device Isolation

ID: 6a744f5e-874e-5048-94c4-6aa070e0fda5

STIX ID: report--6a744f5e-874e-5048-94c4-6aa070e0fda5

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Tushar Subhra Dutta

...
...

## Executive summary: A user-initiated ransomware attempt at QNET used the legitimate Windows utility mshta.exe (living-off-the-land) to retrieve a remote payload. Microsoft Defender detected suspicious RunMRU-related command activity and, via automated correlation and the IsolateDevice playbook, isolated the endpoint within about 128 seconds, stopping further payload download, persistence, or lateral movement; the report emphasizes rapid containment, staff training, hardened scripting controls, and tested backups as key mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.