GitHub & Dropbox Weaponized: “Defendnot” Tool Used to Disable Windows Defender
ID: 5684809f-dc7a-5795-a6a1-a20b0a8e2a2f
STIX ID: report--5684809f-dc7a-5795-a6a1-a20b0a8e2a2f
Feed Name: securityonline.info
Threat Score
### Executive summary FortiGuard Labs uncovered a sophisticated multi-stage campaign targeting users in Russia that leverages social-engineered business documents, abuses the Defendnot research tool to disable Microsoft Defender, and uses GitHub and Dropbox to host modular components; attackers deploy Amnesia RAT for long-term access and end with ransomware/WinLocker to destroy data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
