logo

Fake LDAPNightmware exploit on GitHub spreads infostealer malware

ID: f1f83f86-6f66-52c1-843c-5c77a0c52c00

STIX ID: report--f1f83f86-6f66-52c1-843c-5c77a0c52c00

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-01-11

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Trend Micro identified a deceptive GitHub repository posing as a PoC for CVE-2024-49113 that instead distributes an info-stealer: a UPX-packed 'poc.exe' drops a PowerShell script which schedules encoded tasks, retrieves additional scripts from Pastebin, harvests system/process/network information and uploads it as a ZIP to an external FTP server using hardcoded credentials; IOCs are provided and users are advised to validate PoC sources and inspect binaries before execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.