logo

Hackers exploit Windows SmartScreen flaw to drop DarkGate malware

ID: b48e86d1-44fe-5aba-9761-e9e24001df4a

STIX ID: report--b48e86d1-44fe-5aba-9761-e9e24001df4a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-03-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trend Micro reports that DarkGate operators are exploiting CVE-2024-21412, a Windows Defender SmartScreen bypass, by chaining .url shortcut files to cause remote MSI installers to execute and deploy DarkGate v6 via DLL sideloading; the malware provides data-stealing, keylogging, process injection, and remote access capabilities. The campaign uses phishing emails with open-redirect links, masquerades installers as legitimate software, and includes updated configuration/evasion options; Microsoft patched the flaw in February 2024 and Trend Micro published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.