logo

Multiple Groups Exploit NTLM Flaw in Microsoft Windows

ID: e072c2d3-d104-5a4f-a412-0c7516b59cf8

STIX ID: report--e072c2d3-d104-5a4f-a412-0c7516b59cf8

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-04-16

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Researchers observed multiple active campaigns exploiting CVE-2025-24054, an NTLM hash-disclosure vulnerability patched by Microsoft in March; attackers deliver ZIP archives with a malicious library-ms file that triggers Windows to send NTLM authentication to attacker-controlled SMB servers, enabling harvesting of NTLM hashes. Check Point reported attacks starting eight days after the patch, targeting government and private organizations across several countries and finding related SMB infrastructure in Australia, Bulgaria, the Netherlands, Russia, and Turkey. The exploit requires minimal user interaction (e.g., extracting or navigating to a folder) and is used to facilitate pass-the-hash and relay-style credential misuse, underscoring the need for immediate patching and NTLM mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.