logo

Collateral Damage: Microsoft Defender Blocks Official MAS Script in Malware War

ID: f40ab8eb-2c09-5cc1-b587-7e2639af447a

STIX ID: report--f40ab8eb-2c09-5cc1-b587-7e2639af447a

Feed Name: securityonline.info

Threat Score
45/100

Date Published: 2026-01-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender is reportedly blocking the legitimate Microsoft Activation Scripts (MAS) because it is conflating the genuine domain `get.activated.win` with a malicious lookalike `get.activate.win` used to distribute PowerShell-based malware; Defender flags the activity as `Trojan:PowerShell/FakeMas.DA!MTB`. The report warns that users should not disable security protections to run activation commands, as doing so could allow the phishing/malicious script to execute and lead to compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.