Windows SmartScreen flaw exploited to drop Phemedrone malware
ID: 169941f0-8f30-5d60-b7c3-10d64b7462b7
STIX ID: report--169941f0-8f30-5d60-b7c3-10d64b7462b7
Feed Name: Bleeping Computer
Phemedrone is an open-source information-stealer that leverages a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass Windows warnings via malicious .URL files hosted on trusted services; the dropper downloads a .cpl which launches a PowerShell-based DLL loader and uses DLL side-loading to execute payloads that harvest browser credentials, crypto wallets, Discord/Telegram/Steam data and system files, exfiltrating data (reported via Telegram); Trend Micro and BleepingComputer reported active exploitation and published IoCs, and the vulnerability was patched in November 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
