Security researchers from Fortinet they revealed an attack, which relies on social engineering and abuse of Windows architecture instead of traditional exploits.
The attack shows us that attackers are increasingly targeting user trust and operating system behavior rather than fixable flaws.
Malware bypasses Defender using Windows security logic
Victims receive what appears to be a typical business document inside a compressed archive. The archive contains malicious shortcut files that look like harmless documents. However, once opened, the shortcut runs PowerShell scripts that bypass Windows security policies and download additional malware.
The malware then disables Microsoft Defender by registering a fake antivirus product. Windows automatically disables Defender when it detects another security application, allowing the malware to bypass protections without any alerts.
Attackers also add code to trusted Windows processes, such as Task Manager, to avoid raising suspicion.
The malware disables Task Manager, Registry Editor, Run dialog box, and System Settings via registry policies. It also disables Windows Recovery Environment using administrator commands.
Backup directories disappear and the malware deletes all Volume Shadow Copy snapshots, removing common recovery options. By the time users notice any unusual behavior, system protections are already gone.
All files used for the attack are hosted on legitimate services like GitHub and Dropbox. This tactic helps the malware move in normal network traffic and avoid detection by security tools.
After disabling defenses, the attack deploys the Amnesia RAT, which steals browser data, saved passwords, and cryptocurrency wallet information. The malware then encrypts the user's data, compounding the damage.
This attack stands out because it convinces Windows to disable its own defenses. This approach makes detection and response much more difficult than traditional malware techniques.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.


