MSDT Vulnerability CVE-2022-30190 Exploited For PowerShell
ID: b94c8ec9-5dca-5aea-8bef-f552a8470e78
STIX ID: report--b94c8ec9-5dca-5aea-8bef-f552a8470e78
Feed Name: Cyble Blog
Cyble Research Labs documents active in-the-wild exploitation of CVE-2022-30190 (MSDT/Follina) using malicious RTF files that embed an OLE object to load an HTML exploit which downloads a PowerShell-based information stealer; the stealer harvests browser and application credentials, specific registry keys, runs system discovery commands, compresses data and exfiltrates logs to a public C2 (45.77.156.179). The report provides IoCs (hashes, URLs, IP), MITRE ATT&CK mappings, and remediation recommendations (Microsoft mitigations, MFA, patching, antivirus, DLP, network monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
