Defender Control is a Windows utility used to disable Microsoft Defender protections. It has been abused by financially motivated ransomware operators, including activity associated with Cuba ransomware, to impair endpoint defenses during post-compromise operations. In observed intrusions, operators used it alongside a scheduled task to maintain its execution. The Trigona threat actor has also used Defender Control during compromises of exposed or weakly protected Microsoft SQL Server environments. Defender Control is a dual-use administrative tool rather than a distinct malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actors used Defender Control to disable Microsoft Defender and created a scheduled task to maintain its execution.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Defender Control sets a couple registry values to disable Defender including this one: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware DWORD (0x00000001) Defender Control also sets this value to disable the startup of the Defender service: HKLM\System\CurrentControlSet\Services\WinDefend\Start DWORD (0x00000003)
Defender Control sets a couple registry values to disable Defender including this one: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware DWORD (0x00000001) Defender Control also sets this value to disable the startup of the Defender service: HKLM\System\CurrentControlSet\Services\WinDefend\Start DWORD (0x00000003)
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool referenced as used/available to the actor to weaken or disable Microsoft Defender protections as part of post-compromise activity.
Tool used to disable Microsoft Defender to evade detection; persistence maintained via scheduled task execution.
A tool abused to disable Microsoft Defender antivirus, facilitating defense evasion before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.