logo

Cyberattackers Exploit Microsoft SmartScreen Bug in Stealer Campaign

ID: e27dcff6-6745-562e-a403-7d5738d1f727

STIX ID: report--e27dcff6-6745-562e-a403-7d5738d1f727

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-24

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A high-severity Microsoft Defender SmartScreen bypass (CVE-2024-21412, CVSS 8.1) patched in February is being actively exploited worldwide to deploy infostealers. Attackers deliver LNK files that fetch HTA/PowerShell payloads which decode malicious code hidden inside JPG images via Windows APIs to inject stealers (Meduza, ACR, Lumma, Water Hydra, DarkGate) into legitimate processes, resulting in credential, wallet, and other sensitive data exfiltration from unpatched Windows hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.