Serving regulated mid-market businesses nationwide (888) 901-9686 · support@elevatesolutions.io
← Back to Insights

Windows: New Ransomware Variant Bypasses Defender — What to Check Now

A new ransomware strain is using signed Windows drivers to disable Microsoft Defender before encrypting files. Here's how to detect it and what compensating controls to deploy.

ES
Elevate Solutions
April 22, 2026 · 6 min read

The technique

The variant abuses a legitimately signed but vulnerable driver (a "bring your own vulnerable driver" attack) to terminate Defender and other security agents from kernel space before encryption begins.

What to check now

  • Confirm tamper protection is enabled on Defender and your EDR
  • Enable Microsoft's vulnerable driver blocklist
  • Alert on security-service stop events and unexpected driver loads
  • Verify your EDR reports to a console the attacker can't reach from the endpoint

If you're a managed client

These controls are part of our standard hardening. If you're not sure yours are in place, call us — we'll verify today.

Elevate Solutions' security and IT advisory team delivers managed cybersecurity (MDR/MXDR), managed IT, and compliance guidance (HIPAA, SOC 2, PCI DSS) for regulated mid-market firms across Los Angeles.

Reviewed by David Faramarzi · Founder, Elevate Solutions
Share:
Next story 5 Cybersecurity Mistakes Small Businesses Make in 2026 April 21, 2026 · 6 min read