A Campaign Disables Microsoft Defender Before Dropping Ransomware
The claim has been circulating since July 2, 2026: attackers are allegedly disabling Microsoft Defender, the log-monitoring tool Sysmon, and web application
- The claim has been circulating since July 2, 2026: attackers are allegedly disabling Microsoft Defender, the log-monitoring tool Sysmon, and web application
- Introduction: the claim under review
- What cybersecurity researchers are reporting
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: the claim under review
What cybersecurity researchers are reporting
The claim has been circulating since July 2, 2026: attackers are allegedly disabling Microsoft Defender, the log-monitoring tool Sysmon, and web application firewalls (WAFs) before deploying the credential-theft toolMimikatz. This claim comes directly from the vulnerability intelligence report published by Threat-Modeling.com, a specialized cybersecurity source we were able to review directly.
This fact-check verifies every element of that claim: the exact nature of the technique, its connection to Defender's recent vulnerabilities, and the reliability of the source documenting it. Preliminary verdict: the claim is largely corroborated by the primary source, with a few technical nuances to add.
Claim #1: a three-step attack chain
What the report precisely states
According to Threat-Modeling.com, the campaign follows a precise sequence: attackers first gain initial access to the targeted system, then disable all security monitoring, then harvest user credentials. The report calls this method a sophisticated "defensive kill chain," a technical term that precisely describes this type of cascading attack.
Verdict: TRUE. This description matches exactly what the primary source documents, with no exaggeration or shortcut. The three-stage sequence, access then neutralization then theft, is indeed the classic pattern for this type of attack, widely documented in specialized cybersecurity literature beyond this single report.
Why this sequence is especially dangerous
What makes this attack chain formidable isn't any single stage on its own, but how fast and coordinated the sequence is: once monitoring is neutralized, attackers operate almost blind to security teams, who lose their detection capability at the exact moment the attack becomes most damaging.
This technical reality confirms that detection speed remains the decisive factor in limiting the damage from a modern cyberattack, a principle this report illustrates concretely rather than theoretically.
Claim #2: two distinct Defender vulnerabilities this week
BlueHammer, a confirmed ransomware vector
The report names two specific vulnerabilities affecting Microsoft Defender discovered in the same week: BlueHammer, a privilege escalation flaw tracked as CVE-2026-33825, confirmed by CISA as actively used in real ransomware campaigns.
Verdict: TRUE, with official confirmation. The fact that CISA, the U.S. cybersecurity agency, confirmed active exploitation of this flaw in real ransomware attacks gives this part of the claim considerable factual weight. This isn't a theoretical threat but a documented attack vector in the field.
RoguePlanet, a zero-day still without a full patch
The second vulnerability, dubbed RoguePlanet, is described by the report as a confirmed critical zero-day in the built-in antivirus that ships with every installation of Windows. Microsoft is reportedly working actively on a security patch, but the precise technical details of this flaw remain limited pending its official release.
Verdict: TRUE, but incomplete by nature. A zero-day, by definition, refers to a vulnerability that hasn't been patched at the time of its discovery, which explains why exhaustive technical details aren't yet publicly available. This limitation doesn't undermine the claim's truthfulness — it simply reveals its evolving nature.
Claim #3: two Defender flaws in 48 hours, an unprecedented fact
An unusual concentration of critical vulnerabilities
The report notes that the discovery of two distinct critical vulnerabilities in Microsoft's built-in antivirus within 48 hours is an event it calls "unprecedented." BlueHammer was reportedly disclosed the day before RoguePlanet, according to the precise timeline established in the July 1 report.
Verdict: LIKELY TRUE, pending full historical verification. We could not independently confirm that no similar precedent exists in Microsoft Defender's history, but the specialized source, whose job is to track this type of event daily, states this exceptional nature with a degree of technical authority.
Why Defender's nature amplifies the risk
Discover
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
The report stresses an essential technical point: Defender runs with SYSTEM-level privileges and sits at Windows' deepest trust boundary. Every vulnerability affecting this component therefore represents a potential vector for total system compromise, not a minor flaw limited to some secondary feature.
Verdict: TRUE. This technical characterization of Defender's privilege level matches Windows' known and documented architecture. Security software with such privileges is indeed a prime target precisely because compromising it opens near-total access to the targeted system.
Claim #4: are the defensive recommendations realistic
What experts concretely recommend
The report advises organizations to verify that Defender's tamper protection is enabled, which prevents unauthorized disabling, to monitor Windows event logs for security-service shutdowns, and to set up alerts on any change in Defender's or Sysmon's status.
Verdict: TECHNICALLY VALID RECOMMENDATIONS. These measures match standard industry best practices for this type of threat. They don't guarantee absolute protection, but they significantly reduce the window of opportunity attackers have to operate undetected.
The practical limits of these recommendations
That said, the technical enthusiasm needs tempering: not every organization, especially small operations without a dedicated security team, necessarily has the human and technical resources to implement continuous monitoring of these event logs. The recommendation is technically sound, but its universal applicability is debatable.
This practical limitation doesn't make the recommendation wrong — it simply highlights a persistent gap between theoretical cybersecurity best practices and the real capabilities of the most vulnerable organizations, often the least equipped to defend themselves.
Claim #5: Mimikatz remains a go-to tool for credential theft
An old tool that's still devastatingly effective
The claim that attackers use Mimikatz to siphon credentials once monitoring is disabled rests on a well-established industry fact: this tool, originally developed for security demonstration purposes, remains one of the most widely used credential-theft utilities in real attacks for more than a decade.
Verdict: TRUE and consistent with established trends. The persistence of Mimikatz as a go-to tool, despite its relative age in the threat landscape, is no surprise to anyone following this field: its effectiveness at extracting in-memory credentials remains largely intact against standard defenses not specifically configured to detect it.
What this reveals about organizations' defensive maturity
The fact that such a well-known and documented tool continues to work effectively in contemporary attacks points to a problem bigger than just Defender's vulnerabilities: many organizations still haven't deployed the specific defensive configurations that would let them effectively detect or block Mimikatz use on their systems.
This observation, while not explicitly stated that way in the source report, follows logically from the facts it presents: the defensive technology exists, but its actual deployment remains uneven across organizations.
Claim #6: Microsoft's silence on a patch timeline
What the report criticizes about official communication
The report from Threat-Modeling.com notes that Microsoft has not published a precise timeline for a full RoguePlanet patch, offering only generic acknowledgments through its Microsoft Security Response Center. This lack of transparency on timing feeds uncertainty among security officers who, in the meantime, must apply temporary mitigations rather than a definitive fix.
Verdict: TRUE, but needs nuance. It is common, and even recommended by industry best practice, for vendors not to disclose precise technical details about a patch in progress before its release, in order to avoid handing attackers a roadmap. Microsoft's relative silence isn't necessarily a fault, but it remains frustrating for security teams having to manage risk under uncertainty.
Comparable precedents at other vendors
This dynamic isn't unique to Microsoft: other tech giants like Google and Apple have, in the past, adopted similar staged disclosure policies for critical zero-day vulnerabilities, prioritizing operational security over immediate transparency toward the general public.
Verdict: CONTEXT CONFIRMED. The practice of responsible disclosure, which limits public information until a patch is ready, is a widely accepted norm in the cybersecurity industry, even if it legitimately frustrates system administrators on the front lines against the threat.
Claim #7: the campaign's real scale remains unconfirmed
What the report says, and especially what it doesn't
A close read of the Threat-Modeling.com report reveals an important limitation: the document provides no precise figures on how many organizations have been affected, nor the identity of the ransomware groups involved in this specific campaign. This lack of quantitative data doesn't discredit the claim, but it does limit its exact factual scope.
More analysis
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
Verdict: INCOMPLETE INFORMATION, NOT FALSE. It would be dishonest to claim this campaign hit a specific number of victims without a source confirming it. What can be stated with certainty is that the technique exists, is documented, and that the exploited vulnerabilities are real and confirmed by CISA.
Why this methodological caution matters
This distinction between a confirmed technique and a still-unclear scale illustrates precisely why a rigorous fact-check must resist the temptation to amplify a threat beyond what the sources actually allow us to establish, even when the topic is legitimately concerning for Western organizations' security.
This rigor in no way diminishes the seriousness of the documented threat: it simply clarifies its factual boundaries, allowing security officers to prioritize their efforts on solid ground rather than poorly calibrated panic.
On the same topic
ESSAY: Fourth Heat Wave — Europe Enters the Age…
On July 28, 2026, the New York Times reports that the…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
Conclusion: the overall verdict on the reported campaign
A claim largely corroborated by a reliable specialized source
After verifying every component of this claim, our overall verdict is as follows: the core of the claim is TRUE and well documented by the report from Threat-Modeling.com, itself backed by CISA confirmations regarding the active exploitation of the BlueHammer flaw. The attack chain described, the critical nature of both Defender vulnerabilities, and Mimikatz's role in credential theft all correspond to technically consistent and corroborated facts.
The only reservation concerns the full technical details of RoguePlanet, still limited due to its nature as an incompletely patched zero-day, a limitation inherent to this type of discovery rather than a weakness of the information source itself.
What organizations should take away
Beyond the factual verdict, this fact-check confirms an urgent operational reality: organizations using Windows and Microsoft Defender should treat this information as a legitimate warning signal justifying an immediate review of their security posture, rather than as just another technical curiosity in the constant stream of cybersecurity reports.
By Maxime Marquette, columnist
Columnist's transparency note
Who I am and my acknowledged biases
I approach technology topics with a firm conviction: the West must maintain its technological edge against rivals like China, Russia, Iran, and North Korea, whose offensive cyber capabilities are long documented. That conviction doesn't stop me from rigorously verifying every technical claim before relaying it.
This fact-check relies exclusively on the vulnerability intelligence reports published by Threat-Modeling.com on July 1 and 2, 2026. I did not invent a single technical detail, vulnerability, or quote in this piece.
What I don't know, and my method
I am not a cybersecurity researcher and cannot personally verify the exploit code for these vulnerabilities. My method is to assess the report's internal consistency, its match with known technical facts about Windows architecture, and the credibility of its cited sources, notably CISA, rather than to conclude beyond what these elements reasonably allow.
Sources
Primary sources
Threat-Modeling.com, Vulnerability Intelligence Report — July 2, 2026
Microsoft Security Response Center, official security blog — accessed July 2026
Secondary sources
Threat-Modeling.com, Vulnerability Intelligence Report — July 1, 2026
Cybersecurity and Infrastructure Security Agency (CISA), Known Exploited Vulnerabilities catalog — accessed July 2026
Military Times, context on cyberthreats targeting Western infrastructure — accessed July 2026
Wikipedia, history and function of the Mimikatz tool — accessed July 2026
Get the tech columns
AI, platforms, digital power: the next analyses straight to your inbox.
Cite this article
Maxime Marquette (2026). A Campaign Disables Microsoft Defender Before Dropping Ransomware. MadMax. https://mad-max.co/en/article/une-campagne-desactive-microsoft-defender-avant-de-lacher-les-rancongiciels
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.