Weaponized LDAP Exploit PoC Installs Info-Stealing Malware
ID: 67c7716a-54b4-5d25-abcc-c8fcb59cebb8
STIX ID: report--67c7716a-54b4-5d25-abcc-c8fcb59cebb8
Feed Name: Cyber Press
Microsoft's December 2024 Patch Tuesday fixed two critical LDAP vulnerabilities (CVE-2024-49112 enabling remote code execution and CVE-2024-49113 enabling LDAP service denial-of-service). The report describes a malicious fork of a Python repository that replaced source files with a packed executable (poc.exe) which drops a PowerShell script, creates a scheduled task to run an encoded script, fetches secondary scripts from Pastebin, collects and zips system data, and uploads the archive to an external FTP server using embedded credentials—illustrating how PoC exploits and compromised repositories can be used to distribute malware and exfiltrate data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
