Weaponized LDAP Exploit Deploys Information-Stealing Malware
ID: e0eeaef8-97ea-5462-a3cb-4802502a42bf
STIX ID: report--e0eeaef8-97ea-5462-a3cb-4802502a42bf
Feed Name: GBHackers
Cybercriminals are distributing malicious fake proof-of-concept 'LDAPNightmare' exploits for CVE-2024-49112/49113 by forking legitimate repositories and replacing Python source files with a packed executable (poc.exe). When executed, the binary drops PowerShell scripts that establish persistence via a scheduled task, retrieve additional scripts from Pastebin, collect extensive system data, compress the information, and exfiltrate it (including the victim's public IP) to an external FTP server; defenders are advised to obtain code from trusted sources, review commit history, and verify repository owners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
