Cyberattackers Exploit Microsoft SmartScreen Bug in Stealer Campaign
ID: e27dcff6-6745-562e-a403-7d5738d1f727
STIX ID: report--e27dcff6-6745-562e-a403-7d5738d1f727
Feed Name: Dark Reading
Threat Score
A high-severity Microsoft Defender SmartScreen bypass (CVE-2024-21412, CVSS 8.1) patched in February is being actively exploited worldwide to deploy infostealers. Attackers deliver LNK files that fetch HTA/PowerShell payloads which decode malicious code hidden inside JPG images via Windows APIs to inject stealers (Meduza, ACR, Lumma, Water Hydra, DarkGate) into legitimate processes, resulting in credential, wallet, and other sensitive data exfiltration from unpatched Windows hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
