Hackers used new Windows Defender zero-day to drop DarkMe malware
ID: b708d141-31de-5d63-a6e0-009e83c278d7
STIX ID: report--b708d141-31de-5d63-a6e0-009e83c278d7
Feed Name: Bleeping Computer
Microsoft patched a Windows Defender SmartScreen zero-day (CVE-2024-21412) that was actively exploited by the financially motivated group tracked as Water Hydra / DarkCasino to deliver the DarkMe RAT to foreign exchange traders. The attackers used chained .URL shortcuts and WebDAV components to bypass SmartScreen and Mark-of-the-Web protections, luring targets via compromised trading sites and telegram/forums; Trend Micro published IoCs and analysis and Microsoft released advisories for this and a second SmartScreen zero-day (CVE-2024-21351).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
