Microsoft disclosed that Microsoft Defender XDR automatically disrupted a ransomware intrusion at QNET by isolating an endpoint 128 seconds after the first detection, containing the incident to a single device. According to the incident summary, the attack began when a user opened a malicious file that launched mshta.exe, which then reached out to attacker-controlled infrastructure to retrieve a second-stage payload; Defender also observed signs consistent with persistence preparation through RunMRU registry activity.
Microsoft said its automatic attack disruption capability correlated multiple high-confidence alerts and triggered the IsolateDevice response playbook without SOC intervention, severing command-and-control communications before the attackers could establish persistence, move laterally, or pull down additional payloads. The case was presented as an example of Defender XDR's automated attack disruption workflow, which is designed to autonomously contain active attacks by taking response actions such as device isolation once sufficient confidence thresholds are met.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly described the QNET incident as a case study showing its new automatic device isolation capability disrupting a ransomware-related multi-stage endpoint attack within 128 seconds of first detection. The report said no SOC action was required during the disruption window.
Microsoft published documentation describing automatic attack disruption capabilities in Microsoft Defender XDR, including automated response actions used to contain attacks. The documentation establishes the product capability later referenced in the QNET case study.
At 09:25:28 UTC, device isolation completed successfully on the compromised QNET endpoint, cutting off internal and external network communications except Defender management traffic. Microsoft said the incident remained contained to a single endpoint, with no further malicious activity, persistence, or lateral movement observed after isolation.
At 09:25:16 UTC, Microsoft Defender autonomously launched the IsolateDevice response playbook against the affected QNET endpoint. The action was taken without SOC intervention during the disruption window.
At 09:25:02 UTC, Microsoft Defender's disruption pipeline determined that device isolation was the most effective containment action for the compromised QNET endpoint. This followed multiple high-confidence detections and correlation of the observed attack behavior.
In the QNET incident, a user-opened malicious file launched mshta.exe, which contacted attacker-controlled infrastructure to retrieve and execute a second-stage payload. Microsoft said this execution occurred at approximately 09:23:20 UTC and showed signs of attempted persistence preparation via RunMRU registry activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.