Windows SmartScreen vulnerability exploited by Mispadu trojan (Campaign)
ID: 249c7d06-c9e4-5856-8515-821868766038
STIX ID: report--249c7d06-c9e4-5856-8515-821868766038
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-02-02
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Mispadu Stealer (a Delphi-based LATAM-targeting banking trojan) has been observed exploiting Windows SmartScreen bypass CVE-2023-36025 by delivering specially crafted .url/internet shortcut files (using UNC paths and WebDAV) inside phishing .zip attachments; a November 2023 case recovered a .url that retrieved and executed a malicious binary, indicating active exploitation for targeted data exfiltration and C2 communication in Latin America.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
