logo

Security pros baited with fake Windows LDAP exploit traps

ID: f73a2d45-f236-5f86-b1ee-a3de0cb68a18

STIX ID: report--f73a2d45-f236-5f86-b1ee-a3de0cb68a18

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-01-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Trend Micro identified a counterfeit proof-of-concept for LDAPNightmare (CVE-2024-49113) that included a malicious 'poc.exe' which dropped a PowerShell loader that downloaded and executed an information-stealing script from Pastebin, collecting system, process, directory, and network information; the report warns researchers to treat PoCs from untrusted sources with caution and references related high-severity LDAP fixes (including CVE-2024-49112) and prior nation-state operations targeting security researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.