logo

Weaponized LDAP Exploit PoC Installs Info-Stealing Malware

ID: 67c7716a-54b4-5d25-abcc-c8fcb59cebb8

STIX ID: report--67c7716a-54b4-5d25-abcc-c8fcb59cebb8

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-01-10

Date Updated: 2026-04-19

Author: Kaaviya

...
...

Microsoft's December 2024 Patch Tuesday fixed two critical LDAP vulnerabilities (CVE-2024-49112 enabling remote code execution and CVE-2024-49113 enabling LDAP service denial-of-service). The report describes a malicious fork of a Python repository that replaced source files with a packed executable (poc.exe) which drops a PowerShell script, creates a scheduled task to run an encoded script, fetches secondary scripts from Pastebin, collects and zips system data, and uploads the archive to an external FTP server using embedded credentials—illustrating how PoC exploits and compromised repositories can be used to distribute malware and exfiltrate data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.