Hackers Disable Windows Security With New Malware Attack
ID: 5c4b1633-6d1f-55e3-8ce4-9bafef6160f6
STIX ID: report--5c4b1633-6d1f-55e3-8ce4-9bafef6160f6
Feed Name: TechRepublic Security
A sophisticated multi-stage Windows malware campaign uses business-themed shortcut lures and PowerShell loaders hosted on GitHub and Dropbox to trick users into disabling Microsoft Defender and recovery features; attackers register fake AV products, inject into trusted processes, and modify registry policies to disable protections, then deploy Amnesia RAT, Hakuna Matata ransomware, and WinLocker components to steal credentials and cryptocurrency data while encrypting or locking victims' systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
