Ransomware operators have repeatedly used tools and policy abuse to disable Microsoft Defender before encrypting Windows environments. DFIR reporting documented the freeware utility Defender Control being used in real intrusions by groups such as Dharma, Phobos, and Crysis, typically after access through exposed RDP, to turn off Defender through registry edits, service changes, driver unloading, and local group policy modifications. Separately, LockBit 2.0 automated the same objective at enterprise scale by creating malicious Active Directory group policies on a domain controller, disabling Defender across domain-joined systems, and launching ransomware via scheduled tasks after enumerating hosts with AD and LDAP queries.
More recent intrusions show the tactic evolving beyond simple utilities into BYOVD and broader policy abuse. WithSecure reported that the CrazyHunter ransomware actor used the vulnerable Zemana Anti-Logger driver zam64.sys to disable both Windows Defender and Trend Micro during attacks on Taiwanese hospitals and industrial organizations, including the Mackay Memorial Hospital incident. The operation also used publicly available tooling such as SharpGPOAbuse for lateral movement and persistence, reinforcing that defense evasion through Defender tampering and group policy manipulation remains a practical, low-barrier technique for ransomware actors ranging from smaller crews to more organized operators.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
WithSecure reported that CrazyHunter attacks began in early 2025 and were involved in multiple incidents, mostly targeting hospitals and some industrial organizations in Taiwan.
The DFIR Report attributed YARA rules for DefenderControl.exe and DefenderControl.ini to itself and dated those rules 2020-12-05 to support detection of the utility in intrusions.
The analyzed Defender Control sample was version 1.6, and the report states it was dated 2020-10-12.
The LockBit ransomware operation launched in September 2019 as a ransomware-as-a-service scheme, recruiting affiliates to breach networks and deploy the malware.
The intrusion also used bb.exe to load Donut-generated shellcode from the ransomware payload and gpo.exe identified as SharpGPOAbuse for GPO-based lateral movement and persistence.
WithSecure found the CrazyHunter encrypter was built from the open-source Prince Ransomware builder and appeared in artifacts as go3.exe and crazyhunter.exe.
In the Mackay Memorial Hospital intrusion, the threat actor used the vulnerable Zemana Anti-Logger driver zam64.sys in a BYOVD technique to terminate Windows Defender and Trend Micro protections.
A CrazyHunter ransomware intrusion affected Mackay Memorial Hospital in Taiwan, with the initial access reportedly involving a USB device.
A new LockBit 2.0 capability was observed that, when run on a domain controller, creates group policies to disable Microsoft Defender, pushes them across the domain, and schedules ransomware execution on endpoints.
Samples of LockBit 2.0 were discovered by MalwareHunterTeam and analyzed by BleepingComputer and Vitali Kremez, revealing domain-wide deployment via Active Directory group policies.
The DFIR Report published analysis showing Defender Control had been observed in multiple intrusions, particularly among smaller ransomware operators such as Dharma, Phobos, and Crysis using exposed RDP access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
labs.withsecure.com
Open sourcesordum.org
Open sourcebleepingcomputer.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.