logo

Hackers used new Windows Defender zero-day to drop DarkMe malware

ID: b708d141-31de-5d63-a6e0-009e83c278d7

STIX ID: report--b708d141-31de-5d63-a6e0-009e83c278d7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft patched a Windows Defender SmartScreen zero-day (CVE-2024-21412) that was actively exploited by the financially motivated group tracked as Water Hydra / DarkCasino to deliver the DarkMe RAT to foreign exchange traders. The attackers used chained .URL shortcuts and WebDAV components to bypass SmartScreen and Mark-of-the-Web protections, luring targets via compromised trading sites and telegram/forums; Trend Micro published IoCs and analysis and Microsoft released advisories for this and a second SmartScreen zero-day (CVE-2024-21351).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.