logo

Weaponized LDAP Exploit Deploys Information-Stealing Malware

ID: e0eeaef8-97ea-5462-a3cb-4802502a42bf

STIX ID: report--e0eeaef8-97ea-5462-a3cb-4802502a42bf

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-01-10

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Cybercriminals are distributing malicious fake proof-of-concept 'LDAPNightmare' exploits for CVE-2024-49112/49113 by forking legitimate repositories and replacing Python source files with a packed executable (poc.exe). When executed, the binary drops PowerShell scripts that establish persistence via a scheduled task, retrieve additional scripts from Pastebin, collect extensive system data, compress the information, and exfiltrate it (including the victim's public IP) to an external FTP server; defenders are advised to obtain code from trusted sources, review commit history, and verify repository owners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.