Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Why is this considered as a virus / trojan by Microsoft Defender?

Nicolas MARTIN June 23, 2025

Hello, 

I wanted to try RovoDev CLI. 

I downloaded it, ran `acli rovodev auth login` then `acli rovodev run`.

But this command was canceled by Microsoft Defender: "Trojan:Win32/Wacatac.H!ml"

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3AWin32%2FWacatac.H!ml&threatid=2147814523

2 comments

Comment

Log in or Sign up to comment
Nikola Perisic
Community Champion
June 23, 2025

Hi @Nicolas MARTIN 

That is really strange indeed. You should alert this to Atlassian support: https://support.atlassian.com/contact/#/

Peter Wu
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
June 25, 2025

Hi @Nicolas MARTIN,

We are aware of this issue, and this is due to the fact that fork/exec are potential signals for malware, so "newly" downloaded code that isn't signed has all the hallmarks of being malware according to many detection systems.

If you have downloaded from our official sources, this is a false alarm. We are working on making sure the files are properly signed in our next release.

 

Thank you.

 

TAGS
AUG Leaders

Atlassian Community Events