Skip to main content
Skip to main content

Change logs for security intelligence update version 1.447.128.0

This page lists newly added and updated threat detections included in security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware. If you don’t find the latest security intelligence update version in the selector below, please refresh this page or let us know us know through the feedback smiley.

Looking for the latest update? Download the latest update

Released on

4/2/2026 2:50:30 AM

Added threat detections

Name Severity
Backdoor:MacOS/FlowOffset.B!dha severe
Backdoor:MacOS/FlowOffset.C!dha severe
Behavior:MacOS/NPMPackageJsonReplace.A severe
Behavior:Win32/CVE-2026-3055.DA!MTB severe
Behavior:Win32/Mamadut.IA severe
Behavior:Win32/TalonStrike.A severe
Behavior:Win32/TalonStrike.B severe
Behavior:Win32/TalonStrike.C severe
HackTool:PowerShell/NetScan!MSR high
Ransom:Win64/Uragan.YBF!MTB severe
Ransom:Win64/Vect.A severe
Trojan:AIMCP/MpTestPromptInjection severe
Trojan:MacOS/FlowOffset.A!dha severe
Trojan:MacOS/FlowOffset.D!dha severe
Trojan:MacOS/FlowOffset.E!dha severe
Trojan:MSIL/FormBook.AKT!MTB severe
Trojan:MSIL/QuasarRAT.ASL!MTB severe
Trojan:MSIL/Rozena.BGN!MTB severe
Trojan:MSIL/SnakeLogger.ACTB!MTB severe
Trojan:MSIL/Zucy.CSL!MTB severe
Trojan:PowerShell/AmsiBypass.DB!MTB severe
Trojan:Python/TalonStrike.BB!dha severe
Trojan:VBS/GuLoader.SPH!MTB severe
Trojan:Win32/Banker.LPB!MTB severe
Trojan:Win32/Malcert severe
Trojan:Win32/PlugX.AB!MTB severe
Trojan:Win32/Zusy.GPKF!MTB severe
Trojan:Win64/AbuseCommBack.NA severe
Trojan:Win64/AbuseCommBack.NA!sms severe
Trojan:Win64/AbuseCommMain.NA severe
Trojan:Win64/AbuseCommMain.NA!sms severe
Trojan:Win64/FormBook.GXH!MTB severe
Trojan:Win64/Loader.P!MTB severe
Trojan:Win64/Rozena.MCD!MTB severe
Trojan:Win64/Tedy.GPKC!MTB severe

Updated threat detections

Name Severity
Backdoor:MSIL/DCRat!MTB severe
Backdoor:Win32/Berbew.AA!MTB severe
Backdoor:Win32/Fynloski!rfn severe
Backdoor:Win32/Padodor.SK!MTB severe
Backdoor:Win32/Remcos!rfn severe
Behavior:Win32/Mamadut.DC severe
Behavior:Win64/AbuseCommBack.B!sms severe
Behavior:Win64/AbuseCommMain.B!sms severe
Behavior:Win64/PinkPlankton.A severe
DoS:Win32/WprBlightre!rfn severe
HackTool:Python/Impacket!MSR high
HackTool:Python/PWDump.A!MTB high
HackTool:Python/RemoteShell!MSR high
HackTool:Win32/Crack!MTB high
HackTool:Win32/Keygen high
HackTool:Win32/Meterpreter!rfn high
HackTool:Win32/Offact high
HackTool:Win32/Patcher!MTB high
HackTool:Win32/WebBrowserPassView high
HackTool:Win64/Mimikatz!rfn high
Misleading:Linux/Chisel.A!MTB high
PWS:MSIL/Browsstl!rfn severe
Ransom:Win32/Filecoder!rfn severe
Ransom:Win64/Akira!rfn severe
Ransom:Win64/Genasom!MTB severe
Spammer:HTML/Phish!MSR severe
Trojan:AndroidOS/AVerseFalc!rfn severe
Trojan:AndroidOS/Multiverze!rfn severe
Trojan:HTML/Phish!MSR severe
Trojan:HTML/Phish.SXK!MTB severe
Trojan:HTML/Qakbot!rfn severe
Trojan:HTML/Redirector.SEM!MTB severe
Trojan:HTML/ScrInject.PLJLH!MTB severe
Trojan:HTML/ScrInject.SJKP!MTB severe
Trojan:HTML/ScrInject.SMW!MTB severe
Trojan:JS/Cardst!rfn severe
Trojan:JS/Obfuse!MSR severe
Trojan:JS/Obfuse.RR!MTB severe
Trojan:JS/Redirector.AVSB!MTB severe
Trojan:JS/Remcos.RVA!MTB severe
Trojan:Linux/Multiverze!rfn severe
Trojan:MacOS/PassStealer.D severe
Trojan:MacOS/SuspMalScript.C severe
Trojan:MSIL/AgentTesla!rfn severe
Trojan:MSIL/AsyncRat!rfn severe
Trojan:MSIL/AveMariaRAT!rfn severe
Trojan:MSIL/CoinMiner!rfn severe
Trojan:MSIL/CryptTrickldr!rfn severe
Trojan:MSIL/DllInject.N!MTB severe
Trojan:MSIL/Injector!rfn severe
Trojan:MSIL/Injector.AH!MTB severe
Trojan:MSIL/Jalapeno.ARR!MTB severe
Trojan:MSIL/Taskun!rfn severe
Trojan:MSIL/Vidar!rfn severe
Trojan:MSIL/Zusy.SXC!MTB severe
Trojan:O97M/DDownloader!rfn severe
Trojan:PDF/Phish!MSR severe
Trojan:Python/TlnxStealer.A severe
Trojan:Script/Malgent!MSR severe
Trojan:Script/Multiverze!rfn severe
Trojan:Script/WebShell!MSR severe
Trojan:VBS/Emotet!rfn severe
Trojan:VBS/Obfus!rfn severe
Trojan:VBS/Qakbot!rfn severe
Trojan:Win32/Alevaul!rfn severe
Trojan:Win32/AresLdrCrypt!rfn severe
Trojan:Win32/Bluteal!rfn severe
Trojan:Win32/Boxter!rfn severe
Trojan:Win32/Casdet!rfn severe
Trojan:Win32/CobaltStrike.SD!MTB severe
Trojan:Win32/Copak.GPAB!MTB severe
Trojan:Win32/CoreWarrior.DA!MTB severe
Trojan:Win32/Egairtigado!rfn severe
Trojan:Win32/EncryptTarget.A severe
Trojan:Win32/Eqtonex!bit severe
Trojan:Win32/Etset!rfn severe
Trojan:Win32/Farfli!rfn severe
Trojan:Win32/FlyStudio.PGC!MTB severe
Trojan:Win32/Guloader.K!MTB severe
Trojan:Win32/Injector.RAQ!MTB severe
Trojan:Win32/Injuke!rfn severe
Trojan:Win32/Kepavll!rfn severe
Trojan:Win32/Leonem!rfn severe
Trojan:Win32/LummaStealer severe
Trojan:Win32/LummaStealer!rfn severe
Trojan:Win32/Malgent severe
Trojan:Win32/Malgent!AMTB severe
Trojan:Win32/Malgent!MSR severe
Trojan:Win32/MereTam!rfn severe
Trojan:Win32/Meterpreter.A severe
Trojan:Win32/OusabanSpy.MKN!MTB severe
Trojan:Win32/PlugX.AB!MTB severe
Trojan:Win32/Pomal!rfn severe
Trojan:Win32/Qwexlafiba!rfn severe
Trojan:Win32/Ravartar!rfn severe
Trojan:Win32/Rugmi severe
Trojan:Win32/Seheq!rfn severe
Trojan:Win32/Skeeyah severe
Trojan:Win32/Stealerc!rfn severe
Trojan:Win32/Supma.A severe
Trojan:Win32/Suschil!rfn severe
Trojan:Win32/Tedy!MTB severe
Trojan:Win32/Tiggre!rfn severe
Trojan:Win32/Vundo.AHC!MTB severe
Trojan:Win32/XWorm!rfn severe
Trojan:Win32/Yomal!rfn severe
Trojan:Win32/Zusy.HBE!MTB severe
Trojan:Win32/Zusy.KK!MTB severe
Trojan:Win64/Cerbu!MTB severe
Trojan:Win64/DllHijack.GPKG!MTB severe
Trojan:Win64/Emotetcrypt!rfn severe
Trojan:Win64/IcedID!rfn severe
Trojan:Win64/Loader.P!MTB severe
Trojan:Win64/Malgent!MSR severe
Trojan:Win64/Reconyc!MTB severe
Trojan:Win64/Shelm!rfn severe
Trojan:Win64/Tedy!MTB severe
Trojan:Win64/Tedy.CJ!MTB severe
Trojan:Win64/Tedy.ZJJ!MTB severe
Trojan:Win64/Tnega!MTB severe
Trojan:Win64/Turla!rfn severe
Trojan:Win64/Ulise.SXB!MTB severe
Trojan:Win64/VMProtect!MTB severe
Trojan:Win64/Zusy.PGZI!MTB severe
TrojanClicker:Win32/Doplik.R severe
TrojanDownloader:BAT/QakBotLoader!rfn severe
TrojanDownloader:JS/Qakbot!rfn severe
TrojanDownloader:O97M/Emotet!rfn severe
TrojanDownloader:PDF/Gozi!rfn severe
TrojanDownloader:Script/Malgent.ATP!MSR severe
TrojanDownloader:VBS/TalonStrike.E!dha severe
TrojanDownloader:Win64/Malgent!MSR severe
UwS:MSIL/Malgent!MSR high
VirTool:Win32/Sliver!rfn severe
Worm:Win32/Gamarue!rfn severe