Fake LDAPNightmware exploit on GitHub spreads infostealer malware
ID: f1f83f86-6f66-52c1-843c-5c77a0c52c00
STIX ID: report--f1f83f86-6f66-52c1-843c-5c77a0c52c00
Feed Name: Bleeping Computer
Threat Score
Trend Micro identified a deceptive GitHub repository posing as a PoC for CVE-2024-49113 that instead distributes an info-stealer: a UPX-packed 'poc.exe' drops a PowerShell script which schedules encoded tasks, retrieves additional scripts from Pastebin, harvests system/process/network information and uploads it as a ZIP to an external FTP server using hardcoded credentials; IOCs are provided and users are advised to validate PoC sources and inspect binaries before execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
