logo

Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025

ID: c229e85d-36e2-573d-9a5e-26ea61f77343

STIX ID: report--c229e85d-36e2-573d-9a5e-26ea61f77343

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-11-26

Date Updated: 2026-04-29

Author: Leandro Cuozzo

...
...

This report analyzes a set of NTLM authentication vulnerabilities disclosed in 2024–2025 (CVE-2024-43451, CVE-2025-24054/24071, CVE-2025-33073), documents active exploitation in the wild by actors such as BlindEagle and Head Mare using crafted .url and .library-ms files to leak NTLMv2 hashes and distribute RATs (Remcos, PhantomCore, AveMaria), describes attacker techniques (hash leakage, coercion, NTLM relay/reflection, LSASS dumping), provides IOCs (malicious file types, IPs, manipulated hostnames, registry/service artifacts), and recommends mitigations (disable/limit NTLM, enable signing and EPA, audit NTLM traffic).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.