logo

Windows SmartScreen Bypass Flaw Exploited to Drop DarkGate RAT

ID: 55c8849f-bf86-5b2f-8fe6-b0defb6bf644

STIX ID: report--55c8849f-bf86-5b2f-8fe6-b0defb6bf644

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-03-14

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers observed a mid-January phishing campaign that abused Google DoubleClick open redirects and a Windows SmartScreen bypass (CVE-2024-21412) to deliver fake Microsoft .MSI installers and install the DarkGate RAT (version 6.1.7). DarkGate, a Delphi-based RAT sold as MaaS, includes info-stealing, keylogging, process injection, download-and-execute, and multiple evasions; actors used open redirects plus the SmartScreen bypass to evade defenses. Microsoft has patched CVE-2024-21412; recommended mitigations include applying the patch, user training to avoid installers from untrusted channels, and continuous monitoring of attack surface and assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.