Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment

Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was stopped in just 128 seconds. The mshta.exe process reached out to attacker-controlled infrastructure, retrieved a remote second-stage payload, and began […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: