← Back to feed
Breaches & RansomwareEmerging1 sourceAug 4, 2026 · 17:54via Microsoft Security Blog

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Brief

In this article

  • What is device isolation?
  • Case study: QNET
  • Attack chain overview
  • MITRE ATT&CK techniques observed
  • References
  • Learn more

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Read more on Microsoft Security Blog