Defender

First seen
2022-04-10 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 16:11:18

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Context

Defender is a ransomware family known for targeting critical industries such as financial services, healthcare, and the public sector. It encrypts victims' files and demands a ransom payment in cryptocurrency for the decryption key.

Detection coverage

  • 4 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_PET_Defendercontrol (yara-rule)
  • SIGNATURE_BASE_HKTL_Bluehammer_Apr26 (yara-rule)
  • SIGNATURE_BASE_HKTL_Redsun_Privilege_Escalation_Apr26 (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Disable_Windows_Defender (yara-rule)