Threats Tagged 'windows defender evasion'
View all threats tagged with 'windows defender evasion'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'windows defender evasion'
Click on any threat for detailed analysis and mitigation recommendations
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically... Join the discussion | AlienVault OTX General | 08/04/2026, 18:20:59 UTC Added: 08/05/2026, 09:26:29 UTC |
A sophisticated phishing campaign leverages DocuSign-themed lures to trick victims into installing legitimate remote management software including MeshAgent, ScreenConnect, and SimpleHelp. The operation employs a reusable web kit featuring staged delivery through simulated document loading interfaces, user-agent based targeting that filters for Windows systems while blocking Edge browsers, and Cloudflare Turnstile verification. The campaign demonstrates operational maturity with separate Windows and macOS delivery paths, real-time victim telemetry via Telegram, and VBS deployment scripts that disable Windows Defender and establish persistence through service installation. Active from May through July 2026, the infrastructure rotates across multiple domains using consistent URL patterns to evade detection while abusing trusted IT tools for persistent access. Join the discussion | AlienVault OTX General | 07/21/2026, 11:38:33 UTC Added: 07/21/2026, 22:37:35 UTC |
Salat Stealer is a Go-based information stealer that performs deep system reconnaissance and extracts sensitive data from compromised hosts. It targets browser credentials, cryptocurrency wallets, and communication platforms like Discord and Steam. The malware features advanced surveillance capabilities including desktop streaming, audio/video capture through microphone and webcam, and local file exfiltration. A notable distribution campaign bundled Salat Stealer with Xeno Executor, a gaming utility tool, transforming it into a full compromise vector. The malware employs sophisticated evasion techniques including disabling Windows Defender features through multiple PowerShell scripts, establishing persistence via registry run keys, and using token impersonation of lsass.exe to obtain elevated privileges. Loaders written in batch script and Rust programming language obfuscate deployment and bypass security controls. Join the discussion | AlienVault OTX General | 07/06/2026, 23:30:03 UTC Added: 07/07/2026, 14:14:38 UTC |
A resurgence of malware deploying XMRig cryptominer was discovered in mid-April 2025, coinciding with a rally in Monero cryptocurrency value. The malware uses a multi-staged approach and LOLBAS techniques, leveraging Windows tools like PowerShell for payload delivery, detection evasion, and persistence. The attack chain involves three stages: initial infection via a batch file, persistence establishment, and cryptomining execution. The malware targets diverse countries, including Russia, Belgium, Greece, and China. It disables Windows Update services, evades Windows Defender, and uses scheduled tasks for persistence. The XMRig miner creates registry entries and drops files for continued operation. Despite its simple, unobfuscated nature, the malware proved effective in avoiding detection. Join the discussion | AlienVault OTX General | 07/07/2025, 13:55:35 UTC Added: 07/07/2025, 21:09:24 UTC |
CyberEye is a modular, .NET-based Remote Access Trojan that utilizes Telegram for Command and Control, eliminating the need for attackers to maintain their own infrastructure. It offers a wide array of surveillance and data theft capabilities, including keylogging, file grabbing, and clipboard hijacking. The malware employs advanced defense evasion techniques, disabling Windows Defender through PowerShell and registry manipulations. Its modules harvest browser credentials, Wi-Fi passwords, gaming profiles, and session data from various applications. The builder framework allows adversaries to customize payloads, making it accessible to less technically skilled threat actors. CyberEye's persistence mechanisms, anti-analysis features, and use of public messaging platforms for C2 make it a significant threat to both consumers and enterprises. Join the discussion | AlienVault OTX General | 06/13/2025, 07:40:42 UTC Added: 06/13/2025, 08:19:24 UTC |
Showing 1 to 5 of 5 results