Hackers Weaponize Windows Flaw to Deploy Crypto-Siphoning Phemedrone Stealer
ID: 28e901b3-0842-57f5-bebd-213f400d0fa5
STIX ID: report--28e901b3-0842-57f5-bebd-213f400d0fa5
Feed Name: The Hacker News
Trend Micro researchers observed threat actors actively exploiting CVE-2023-36025 (Windows SmartScreen bypass, CVSS 8.8) to distribute Phemedrone Stealer: malicious .URL files hosted on Discord and file-hosting services trigger a .CPL executed via rundll32, which loads a PowerShell stage (DATA3.txt) that uses Donut to decrypt/execute the Phemedrone stealer; the stealer targets browsers, cryptocurrency wallets and messaging apps and exfiltrates stolen data via Telegram or C2. Microsoft patched the vulnerability in November 2023, but actors continue to adapt the chain to evade SmartScreen and deploy stealers and other malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
