Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are abusing Microsoft Defender Antivirus exclusions to keep malicious files outside routine security scans. Rather than switching protection off completely, attackers can leave antivirus running while creating gaps around malware staging folders and selected file types.

This is an established evasion technique, not a new malware family. It requires administrator privileges or higher, making it a step after attackers gain sufficient control.

Separate reporting on fake Claude desktop installers shows how malicious downloads can lead to exclusion changes that shelter remote access malware. Huntress researchers identified wider use of this overlooked technique during their investigation.

Huntress said in a report shared with Cyber Security News (CSN) that exclusions can offer attackers a quieter alternative to disabling antivirus altogether, while the security application remains active.

The September 30 report connects the behavior to GootKit in 2019, WhisperGate in 2022, and Muddled Libra in 2024. It does not provide a reported victim count, but highlights a recurring weakness: legitimate security settings can become hiding places when attackers control their configuration.

Hackers Abuse Microsoft Defender Exclusions

Defender supports exclusions for paths, file extensions, processes, and IP addresses. Their effects include skipping selected files during scans or excluding specified network traffic from inspection.

For attackers, Huntress identified path and extension exclusions as useful for reducing visibility. A path exclusion can shelter an entire directory rather than one file. An extension exclusion can exempt files sharing a particular suffix.

Huntress describes these categories as removing matching content from scheduled, on demand, and real time scanning, allowing malicious binaries to avoid those checks.

Attackers have several routes to make these changes. PowerShell commands, Windows Management Instrumentation, Group Policy, and direct registry changes can all interact with exclusion settings.

These are Windows administration mechanisms, so detecting abuse requires examining what changed and why, rather than treating every administrative operation as malicious.

Registry activity shown by ProcMon (Source - Huntress)
Registry activity shown by ProcMon (Source – Huntress)

PowerShell changes pass through Windows management components before the Defender service updates its registry configuration. Group Policy uses a separate policy location.

Normally, querying exclusions returns settings from both sources, meaning responders must consider local antivirus configuration and centrally managed policies during ongoing investigations.

Direct editing of Defender’s own exclusions registry location is restricted, according to the report. However, attackers can modify the corresponding Group Policy location instead.

Huntress notes that this particular policy change requires a reboot to take effect, a detail that matters when reconstructing an intrusion.

The approach also appears alongside other evasion methods. Reporting on ClickFix malware delivery attacks documented exclusion abuse during an intrusion that later stopped Defender entirely, illustrating how attackers can change tactics when one method proves insufficient.

Hidden Exclusions

Huntress also examined a policy setting that hides exclusions from local administrators querying them through PowerShell.

Despite its name, the same setting prevented queries made under SYSTEM, a privileged Windows account. That can create a misleading impression that no exclusions exist when the configuration has simply been concealed.

The settings are not inaccessible, however. Administrators and SYSTEM users can still read the underlying registry data directly. The distinction matters for incident response: an empty result from a query should not be treated as proof that antivirus settings are untouched.

Registry monitoring provides a broader view because exclusion changes ultimately reach the registry regardless of the administration method used.

Huntress described collecting those operations and detecting suspicious exclusions, including broad drive exclusions and commonly abused staging directories. It also monitors changes to the policy that conceals exclusions.

This behavioral approach complements investigations into commercial malware crypter services, where security changes can reveal activity that disguised files alone may not expose.

Teams reviewing a suspected intrusion should examine exclusion creation and concealment together, rather than relying solely on whether antivirus appears enabled.

The source publishes no malicious domains, IP addresses, or file hashes. The following table preserves its filenames, paths, and registry references as contextual investigation artifacts, not standalone proof of compromise.

Legitimate Windows components and example directories should not be blocked solely because they appear here.

Indicators of compromise (IoCs):-

Type Indicator Description
File name MsMpEng.exe Legitimate Defender executable that updates the local exclusions registry configuration.
File name svchost.exe Legitimate Windows service host associated with Group Policy processing, not a malicious binary identified by the report.
File path C:Windowssystem32svchost.exe Service host path shown in the report’s Group Policy execution example.
Directory path C: Entire drive exclusion associated with WhisperGate and highlighted as suspicious when excluded broadly.
Directory path C:Temp Example exclusion target in the PowerShell, WMI, and registry commands.
Directory path C:temp Alternate capitalization used in the Group Policy illustration and accompanying explanation.
Directory name Temp Directory name highlighted when describing suspicious exclusions.
Directory name Downloads Directory name highlighted when describing suspicious exclusions.
Registry key HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows DefenderExclusions Local Defender exclusions configuration updated through the antivirus service.
Registry key HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindows DefenderExclusions Separate Group Policy exclusions configuration described in the report.
Registry key HKLMSOFTWAREPoliciesMicrosoftWindows DefenderExclusionsPaths Policy location used in the direct registry modification example.
Registry value path HKLMSOFTWAREPoliciesMicrosoftWindows DefenderHideExclusionsFromLocalAdmins Setting that conceals exclusions from PowerShell queries by local administrators and SYSTEM users.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans appeared first on Cyber Security News.