Hackers exploit Windows SmartScreen flaw to drop DarkGate malware
ID: b48e86d1-44fe-5aba-9761-e9e24001df4a
STIX ID: report--b48e86d1-44fe-5aba-9761-e9e24001df4a
Feed Name: Bleeping Computer
Trend Micro reports that DarkGate operators are exploiting CVE-2024-21412, a Windows Defender SmartScreen bypass, by chaining .url shortcut files to cause remote MSI installers to execute and deploy DarkGate v6 via DLL sideloading; the malware provides data-stealing, keylogging, process injection, and remote access capabilities. The campaign uses phishing emails with open-redirect links, masquerades installers as legitimate software, and includes updated configuration/evasion options; Microsoft patched the flaw in February 2024 and Trend Micro published IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
