Microsoft Defender Halts QNET Ransomware Attack in Just Over Two Minutes

Microsoft says its automated attack disruption technology isolated an infected endpoint within 128 seconds, preventing a ransomware campaign from spreading across the victim’s environment.

Microsoft has highlighted a recent ransomware incident in which its Defender security platform automatically contained a QNET ransomware attack before it could move laterally through an organization’s network. According to the company, the infected endpoint was isolated within 128 seconds of malicious activity being detected, significantly limiting the attack’s impact.

The response relied on Microsoft Defender’s Automatic Attack Disruption capabilities, which analyze signals across endpoints, user identities, email, cloud services, and other telemetry sources to identify high–confidence attacks in progress. Once the platform determined that the activity matched ransomware behavior, it automatically disconnected the affected device from the network while maintaining its connection to Microsoft Defender for continued monitoring and investigation.

By isolating the compromised workstation so quickly, Microsoft said the system prevented attackers from expanding their foothold, stealing additional credentials, or encrypting systems elsewhere in the environment. Automated containment is designed to reduce the time between detection and response, particularly during fast–moving ransomware campaigns where delays can significantly increase damage.

The incident also reflects Microsoft’s broader effort to automate incident response. In recent months, the company introduced automatic device isolation as part of Defender for Endpoint’s attack disruption framework. The feature, currently available in preview, enables compromised managed workstations to be quarantined automatically without waiting for manual action from security teams.

Microsoft says organizations can later release isolated devices after completing their investigation and remediation. While automation can dramatically shorten response times, security teams are still expected to review incidents, verify the scope of an attack, and restore affected systems when appropriate.

Key Takeaways
  • Microsoft reported stopping a QNET ransomware attack by automatically isolating the compromised endpoint in 128 seconds.
  • Automatic Attack Disruption uses cross–domain security telemetry to detect and contain active attacks.
  • The isolated device remained connected to Microsoft Defender for monitoring while being cut off from the organization’s network.
  • Rapid containment is intended to prevent lateral movement, credential theft, data exfiltration, and ransomware encryption.
  • Automatic device isolation is part of Microsoft Defender for Endpoint’s broader automated response capabilities.