logo

APT Upgrades With Windows Kernel Zero-Day Exploit

ID: c2965750-896b-51ee-aaaf-380b54f1579c

STIX ID: report--c2965750-896b-51ee-aaaf-380b54f1579c

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2024-11-08

Date Updated: 2026-07-20

...
...

Cyble reports that the Bitter APT (T-APT-17) has been observed exploiting a Windows kernel privilege-escalation zero-day (CVE-2021-1732) in the wild to elevate process tokens to SYSTEM and deploy a RAT (dllhost.exe) via a self-extractor decoy; the analysis details exploit mechanics (win32kfull.sys / ClientAllocWindowClassExtraBytes callback), post-exploit behavior (memory execution, system enumeration, HTTP-based C2), provides IOCs (file hashes, C2 IPs/URLs), a YARA rule, and recommended mitigations (patching, AV updates, IOC hunting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.