Microsoft Stops Ransomware Attack in 128 Seconds with New Defender Feature
Ransomware attacks are on the rise, with reported incidents increasing year-over-year. In an effort to combat this growing threat, Microsoft has developed a new response action within its Defender tool that can isolate compromised endpoints in just 128 seconds.
Recently, QNET, a global multi-level marketing and direct-selling company, was targeted by ransomware actors who employed a legitimate Windows tool on a compromised endpoint to fetch the malicious remote ransomware payload. The attackers' use of a living-off-the-land technique allowed them to evade defenses.
Microsoft's new device isolation feature can break the lateral movement opportunity, giving security teams time to respond. In the case of the QNET attack, this meant containing the threat early before it had a chance to spread.
Trey Ford, chief strategy and trust officer at Bugcrowd, emphasizes that while device isolation is an important tool in combating ransomware, it is not a substitute for foundational controls such as privileged account management, careful inventory of service accounts, and multi-factor authentication.