logo

Hackers Disable Windows Security With New Malware Attack

ID: 5c4b1633-6d1f-55e3-8ce4-9bafef6160f6

STIX ID: report--5c4b1633-6d1f-55e3-8ce4-9bafef6160f6

Feed Name: TechRepublic Security

Threat Score
80/100

Date Published: 2026-01-23

Date Updated: 2026-04-23

Author: TechRepublic Staff

...
...

A sophisticated multi-stage Windows malware campaign uses business-themed shortcut lures and PowerShell loaders hosted on GitHub and Dropbox to trick users into disabling Microsoft Defender and recovery features; attackers register fake AV products, inject into trusted processes, and modify registry policies to disable protections, then deploy Amnesia RAT, Hakuna Matata ransomware, and WinLocker components to steal credentials and cryptocurrency data while encrypting or locking victims' systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.