logo

Hackers Weaponize Windows Flaw to Deploy Crypto-Siphoning Phemedrone Stealer

ID: 28e901b3-0842-57f5-bebd-213f400d0fa5

STIX ID: report--28e901b3-0842-57f5-bebd-213f400d0fa5

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Trend Micro researchers observed threat actors actively exploiting CVE-2023-36025 (Windows SmartScreen bypass, CVSS 8.8) to distribute Phemedrone Stealer: malicious .URL files hosted on Discord and file-hosting services trigger a .CPL executed via rundll32, which loads a PowerShell stage (DATA3.txt) that uses Donut to decrypt/execute the Phemedrone stealer; the stealer targets browsers, cryptocurrency wallets and messaging apps and exfiltrates stolen data via Telegram or C2. Microsoft patched the vulnerability in November 2023, but actors continue to adapt the chain to evade SmartScreen and deploy stealers and other malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.