A particularly sophisticated malware campaign has raised alarm in the cybersecurity community, as it targets Windows by leveraging social engineering, native operating system tools, and popular cloud services. The attack stands out not for exploiting unknown security vulnerabilities, but for its “clever” misuse of legitimate functions, which makes it extremely difficult to detect.

Misleading documents as a Trojan horse
The infection starts with seemingly harmless files with business or accounting content, which are sent to victims via email or other communication channels. These documents act as bait, inducing users to unzip files containing malicious LNK-type shortcuts.
See also: Abuse of Zendesk to send spam emails
These shortcuts are disguised as regular office files, but in reality they execute PowerShell commands in the background, without being immediately noticeable to the user.
PowerShell and cloud services in focus
Running the shortcut activates PowerShell by bypassing execution policies, downloading an initial load script from repositories on GitHub. The use of popular cloud platforms, such as GitHub and Dropbox, allows the malware to “hide” within normal business network traffic, drastically reducing the likelihood of detection by traditional antiviruses.
This strategy clearly shows the attackers' shift towards "living off the land" techniques, where the very tools of the system are turned into weapons.

Targeted Microsoft Defender Destruction
One of the most concerning aspects of the campaign is the systematic disabling of Microsoft Defender . Fortinet researchers have identified that the attackers are leveraging Defendnot , a research tool originally created to expose vulnerabilities in Windows Security Center.
See also: When training tools become a gateway to cloud attacks
The tool is maliciously reused to register a fake antivirus, exploiting Windows trust mechanisms. As a result, the system automatically disables Defender, leaving the device fully exposed.
Four stages of violation
The attack evolves in four distinct phases. Initially, a persistence mechanism so that the malware survives after reboots, while misleading documents to distract the user.
This is followed by a reconnaissance and surveillance phase, with the installation of screenshot capture tools that record the victim's activity. The data is sent to the attacker via the Telegram Bot API, confirming the successful breach.
System lock and loss of control
Once the necessary information is collected, the attackers proceed to completely lock down the system. They disable management tools, destroy recovery mechanisms , and alter file associations, preventing legitimate applications from running.
See also: LastPass: New phishing attack steals master passwords
At this stage, the victim essentially loses all control of their device, while recovery becomes extremely difficult without specialized intervention.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ransomware and remote control
The final phase involves the installation of the Amnesia RAT, which allows for continuous remote access and extensive data theft. Browser credentials, cryptocurrency wallets, and sensitive financial information are targeted.
Meanwhile, the Hakuna Matata encrypts files with the NeverMind12F, while WinLocker components display lock screens with countdown timers, pressuring victims to negotiate a ransom.
A bell for Windows security
This campaign is a clear indication that modern threats don’t necessarily need zero-day exploits. The misuse of legitimate tools, combined with social engineering and cloud infrastructure, is enough to bypass even strong defenses, making user education and multi-layered security more critical than ever.
