Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025
ID: c229e85d-36e2-573d-9a5e-26ea61f77343
STIX ID: report--c229e85d-36e2-573d-9a5e-26ea61f77343
Feed Name: Securelist by Kaspersky
This report analyzes a set of NTLM authentication vulnerabilities disclosed in 2024–2025 (CVE-2024-43451, CVE-2025-24054/24071, CVE-2025-33073), documents active exploitation in the wild by actors such as BlindEagle and Head Mare using crafted .url and .library-ms files to leak NTLMv2 hashes and distribute RATs (Remcos, PhantomCore, AveMaria), describes attacker techniques (hash leakage, coercion, NTLM relay/reflection, LSASS dumping), provides IOCs (malicious file types, IPs, manipulated hostnames, registry/service artifacts), and recommends mitigations (disable/limit NTLM, enable signing and EPA, audit NTLM traffic).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
