logo

Windows SmartScreen flaw exploited to drop Phemedrone malware

ID: 169941f0-8f30-5d60-b7c3-10d64b7462b7

STIX ID: report--169941f0-8f30-5d60-b7c3-10d64b7462b7

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Phemedrone is an open-source information-stealer that leverages a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass Windows warnings via malicious .URL files hosted on trusted services; the dropper downloads a .cpl which launches a PowerShell-based DLL loader and uses DLL side-loading to execute payloads that harvest browser credentials, crypto wallets, Discord/Telegram/Steam data and system files, exfiltrating data (reported via Telegram); Trend Micro and BleepingComputer reported active exploitation and published IoCs, and the vulnerability was patched in November 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.