Skip to main content
Skip to main content

Change logs for security intelligence update version 1.445.382.0

This page lists newly added and updated threat detections included in security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware. If you don’t find the latest security intelligence update version in the selector below, please refresh this page or let us know us know through the feedback smiley.

Looking for the latest update? Download the latest update

Released on

3/6/2026 10:11:11 AM

Added threat detections

Name Severity
Behavior:Win32/Mamadut.HS severe
Exploit:Win32/CscriptStartup.MK severe
Exploit:Win32/CVE-2025-8088.AM severe
Exploit:Win32/MshtaStartup.MK severe
Exploit:Win32/MshtaTemplate.MK severe
Exploit:Win32/WscriptStartup.MK severe
Ransom:Win64/Malgent!MSR severe
Trojan:JS/FakeCaptcha!MTB severe
Trojan:JS/Powdow.AB!MTB severe
Trojan:JS/PsDownload.AB!MTB severe
Trojan:MSIL/PureLogStealer.AORB!MTB severe
Trojan:MSIL/SalatStealer.APRB!MTB severe
Trojan:PowerShell/GuLoader.PAC!MTB severe
Trojan:PowerShell/Powdow.AE!MTB severe
Trojan:PowerShell/Powdow.AQRB!MTB severe
Trojan:PowerShell/Powdow.PGPO!MTB severe
Trojan:VBS/Obfuse.PGOB!MTB severe
Trojan:VBS/Powdow.AB!MTB severe
Trojan:Win32/Neoreblamy.NUG!MTB severe
Trojan:Win64/ReverseShell.KKA!MTB severe
TrojanDownloader:Win32/Phorpiex.AH!MTB severe
TrojanDropper:MSIL/Tedy.MK!MTB severe
VirTool:MSIL/AmsiSuspClickfix.G severe
VirTool:O97M/Empire.M severe
VirTool:O97M/Empire.N severe
VirTool:O97M/Empire.O severe
VirTool:O97M/Empire.P severe
VirTool:Script/AmsiSuspClickfix.G2 severe

Updated threat detections

Name Severity
Adware:Win32/Tnega high
Adware:Win32/Tnega!MSR high
Backdoor:Linux/Mirai!MSR severe
Backdoor:MSIL/Bladabindi!rfn severe
Backdoor:MSIL/XWormRAT!rfn severe
Backdoor:Win32/Coroxy!rfn severe
Backdoor:Win32/Plugx severe
Backdoor:Win64/Supper!rfn severe
Behavior:Win32/Mamadut.BT severe
Behavior:Win32/Mamadut.CZ severe
Behavior:Win32/Mamadut.EN severe
Behavior:Win32/Mamadut.R severe
Behavior:Win32/PossibleDllHijackExecFlow.BA severe
Behavior:Win32/PossibleDllHijackExecFlowTracking.BA severe
Behavior:Win32/SuspRegService.AM severe
Behavior:Win32/SuspRegService.MK severe
DoS:Win32/FoxBlade!rfn severe
FriendlyFiles low
HackTool:PowerShell/DumpDBCreds!rfn high
HackTool:PowerShell/PowerView!pz high
HackTool:Win32/Activator!MTB high
HackTool:Win32/Agent high
HackTool:Win32/Crack!MSR high
HackTool:Win32/Crack!MTB high
HackTool:Win32/Netcat high
HackTool:Win32/Patcher high
MonitoringTool:AndroidOS/Cerberus.A!MTB severe
Ransom:Linux/CerberRansom!rfn severe
Ransom:Win32/Basta!rfn severe
Ransom:Win32/BlackCat!rfn severe
Ransom:Win32/Clop!rfn severe
Ransom:Win32/ContiCrypt!rfn severe
Ransom:Win32/Genasom!rfn severe
Ransom:Win32/Gocrypt!rfn severe
Ransom:Win32/Royal!rfn severe
Ransom:Win64/Akira!rfn severe
Ransom:Win64/Basta!rfn severe
Ransom:Win64/Filecoder!rfn severe
Trojan:AndroidOS/AVerseFalc!rfn severe
Trojan:AndroidOS/Obfus.D!MTB severe
Trojan:BAT/Qakbot!rfn severe
Trojan:HTML/Phish.AHA!MTB severe
Trojan:HTML/Pterodo!rfn severe
Trojan:HTML/Qakbot!rfn severe
Trojan:HTML/Redirector.SEU!MTB severe
Trojan:HTML/ScrInject.SJKP!MTB severe
Trojan:HTML/ScrInject.SMW!MTB severe
Trojan:JS/Cryxos.AH!MTB severe
Trojan:JS/Obfuse.PAF!MTB severe
Trojan:JS/Qakbot!rfn severe
Trojan:JS/Redirector.AHC!MTB severe
Trojan:Linux/Multiverze!rfn severe
Trojan:Linux/SAgnt!MSR severe
Trojan:MSIL/AgentTesla.AC!MTB severe
Trojan:MSIL/Remcos.AB!MTB severe
Trojan:MSIL/ShellCodeRunner.GPSD!MTB severe
Trojan:PDF/Phish!rfn severe
Trojan:PowerShell/Asyncrat!rfn severe
Trojan:PowerShell/Malgent!MSR severe
Trojan:PowerShell/Obfuscator.PGAH!MTB severe
Trojan:PowerShell/Powdow.AD!MTB severe
Trojan:Python/Nuitka!MTB severe
Trojan:Python/Runner!MTB severe
Trojan:Script/SvgStealer.AR!MTB severe
Trojan:Script/Wacatac severe
Trojan:VBS/Emotet!rfn severe
Trojan:VBS/Obfuse!rfn severe
Trojan:VBS/Obfuse.ZAJ severe
Trojan:VBS/Pterodo!rfn severe
Trojan:VBS/Qakbot!rfn severe
Trojan:VBS/Redirector.SLPM!MTB severe
Trojan:Win32/Alevaul!rfn severe
Trojan:Win32/Amadey!rfn severe
Trojan:Win32/Azorult!rfn severe
Trojan:Win32/Casdet!rfn severe
Trojan:Win32/Coroxy!rfn severe
Trojan:Win32/CryptInject!rfn severe
Trojan:Win32/EBook!MTB severe
Trojan:Win32/Egairtigado!rfn severe
Trojan:Win32/Etset!rfn severe
Trojan:Win32/Fareit.VB!MTB severe
Trojan:Win32/Farfli.AHD!MTB severe
Trojan:Win32/Fauppod!rfn severe
Trojan:Win32/Hive!MTB severe
Trojan:Win32/Hive!rfn severe
Trojan:Win32/Kepavll!rfn severe
Trojan:Win32/KoiLoader!rfn severe
Trojan:Win32/Leonem!rfn severe
Trojan:Win32/Malex!rfn severe
Trojan:Win32/Malgent severe
Trojan:Win32/Malgent!MSR severe
Trojan:Win32/MalInject.A severe
Trojan:Win32/MereTam!rfn severe
Trojan:Win32/Occamy!rfn severe
Trojan:Win32/Occamy.CE3 severe
Trojan:Win32/PersistInStartupDir.A severe
Trojan:Win32/PersistInStartupDir.B severe
Trojan:Win32/PersistInStartupDir.C severe
Trojan:Win32/Salgorea.C!MTB severe
Trojan:Win32/Seheq!rfn severe
Trojan:Win32/SelfDel.A!MTB severe
Trojan:Win32/ShortSeek!rfn severe
Trojan:Win32/Supma.A severe
Trojan:Win32/Suschil!rfn severe
Trojan:Win32/Tedy!MTB severe
Trojan:Win32/Wacatac severe
Trojan:Win32/Yomal!rfn severe
Trojan:Win32/Znyonm!rfn severe
Trojan:Win32/Zusy.BL!MTB severe
Trojan:Win64/Aotera.KK!MTB severe
Trojan:Win64/BazaarLoader!rfn severe
Trojan:Win64/CobaltStrike!rfn severe
Trojan:Win64/CoinMiner!rfn severe
Trojan:Win64/CryptInject!rfn severe
Trojan:Win64/Emotetcrypt!rfn severe
Trojan:Win64/IcedID!rfn severe
Trojan:Win64/Latrodectus!rfn severe
Trojan:Win64/MalDrv!MSR severe
Trojan:Win64/Malgent!MSR severe
Trojan:Win64/Mikey.AH!MTB severe
Trojan:Win64/ReverseShell.KK!MTB severe
Trojan:Win64/SpyLoader!rfn severe
TrojanDownloader:JS/Qakbot!rfn severe
TrojanDownloader:O97M/Emotet!rfn severe
TrojanDownloader:VBS/Tnega!rfn severe
TrojanDownloader:Win32/ShortSeek!rfn severe