Defender
- First seen
- 2022-04-10 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 16:11:18
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector
Context
Defender is a ransomware family known for targeting critical industries such as financial services, healthcare, and the public sector. It encrypts victims' files and demands a ransom payment in cryptocurrency for the decryption key.
Detection coverage
- 4 YARA rules
Detection rules
- DITEKSHEN_INDICATOR_TOOL_PET_Defendercontrol (yara-rule)
- SIGNATURE_BASE_HKTL_Bluehammer_Apr26 (yara-rule)
- SIGNATURE_BASE_HKTL_Redsun_Privilege_Escalation_Apr26 (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Disable_Windows_Defender (yara-rule)