Why we update... Data-thief malware exploits SmartScreen on unpatched Windows PCs
ID: 69dffee4-9ed6-5ef0-8a0a-5d041bca8e2f
STIX ID: report--69dffee4-9ed6-5ef0-8a0a-5d041bca8e2f
Feed Name: The Register (Security)
Trend Micro researchers report that attackers are exploiting CVE-2023-36025 — a Windows Defender SmartScreen bypass — to distribute the Phemedrone info-stealer. The campaign uses a malicious .url that sidesteps SmartScreen to load a .cpl (DLL) which launches PowerShell loaders hosted on GitHub; a chained payload sideloads a malicious DLL and ultimately deploys an RC4-encrypted Phemedrone binary that steals passwords, cookies, authentication tokens, crypto wallet files, and other sensitive data, exfiltrating via Telegram or C2. Microsoft patched the vulnerability in November; organizations should apply updates and monitor for the described loader and sideloading behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
