Hackers Exploit Defender To Hijack Systems
HighExecutive Summary
Threat actors are actively exploiting three recently disclosed zero-day vulnerabilities in Microsoft Defender-dubbed BlueHammer, RedSun, and UnDefend-to gain elevated privileges and disrupt security updates. While Microsoft has patched the BlueHammer flaw (CVE-2026-33825), the remaining two vulnerabilities currently have an unpatched status and remain actively weaponized in the wild.
Vulnerability Details
- Affected Product: Microsoft Defender (Windows Defender) [versions prior to April 2026 updates]
- Identifier: CVE-2026-33825 (BlueHammer)
- CVSS Score: 7.8 (High)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Critical urgency for patching BlueHammer; high vigilance required for the remaining unpatched flaws.
- Attack Vector: Attackers use local privilege escalation (LPE) via Volume Shadow Copy abuse to gain SYSTEM-level control, alongside denial-of-service (DoS) tactics to block definition updates.
- Ease of Exploit: Low complexity; proof-of-concept (PoC) code is publicly available on GitHub and actively used.
Action Plan
- Immediate Action: Apply the April 2026 Patch Tuesday updates / Upgrade to Version April 2026 Update.
- Workaround: Isolate affected systems and treat any remote access credential compromise as a high-severity incident.
- Detection: Monitor for suspicious enumeration commands such as
whoami /priv, cmdkey /list, and net group.
Relevant professional terms
- Local Privilege Escalation (LPE)
- A cyberattack technique where an attacker with limited user access exploits a vulnerability to gain higher-level permissions, such as administrator or SYSTEM rights.
- Zero-Day Vulnerability
- A software security flaw that is known to attackers or researchers but does not yet have an official patch or fix from the vendor.
Sanctioned Grinex Exchange Collapses After $13.7M Hack
Executive Summary
Grinex, a Kyrgyzstan-registered cryptocurrency exchange sanctioned by the U.S., U.K., and EU, suspended operations after attackers drained over $13.7 million (approximately 1 billion rubles) from user wallets. The platform-widely identified as a rebrand of sanctioned Russian exchange Garantex-attributed the breach to foreign state-backed actors, though no technical evidence supporting that claim has been published.
Attack Overview
- Attack Path: Attackers compromised 54 exchange wallets on April 15, 2026, at approximately 12:00 UTC. Stolen USDT was rapidly transferred to TRON and Ethereum addresses and converted into TRX and ETH via the SunSwap decentralized trading protocol to avoid Tether freezing the funds.
- Attacker: Unknown (Grinex claims foreign intelligence involvement; independent blockchain analysts have not confirmed attribution)
Impact Assessment
- Data Stolen: Over $13.7 million in cryptocurrency drained from 54 user wallets, primarily USDT on the TRON blockchain. Elliptic tracked approximately $15 million in total outgoing transfers.
- Operational Impact: Grinex suspended all trading operations; users cannot access funds. A simultaneous breach at TokenSpot, a related Kyrgyzstan-based exchange, resulted in an additional theft of under $5,000.
Detection & Hunting
- IOCs: TRM Labs identified approximately 70 attacker wallet addresses across TRON and Ethereum; consolidated attacker wallet holds ~45.9 million TRX (~$15M).
- Detection Guidance: Monitor for USDT-to-TRX/ETH conversion patterns via SunSwap and flag transactions originating from the 54 published compromised wallet addresses.
Strategic Takeaway
Sanctioned exchanges operating as rebrands of seized predecessors remain high-value targets. The rapid conversion of stolen stablecoins into native tokens to evade issuer freezes demonstrates an evolving laundering playbook that compliance and blockchain intelligence teams must anticipate.
Relevant professional terms
- Stablecoin
- A cryptocurrency designed to maintain a stable value by pegging it to a reserve asset such as a fiat currency, used extensively in cross-border transactions and sanctions evasion schemes.
- Sanctions Evasion
- The use of financial tools, shell companies, or rebranded platforms to circumvent economic restrictions imposed by governments on designated entities or countries.