DarkMe Malware Targets Traders Using Microsoft SmartScreen Zero-Day Vulnerability
ID: 39b82d9e-a2c1-5d25-ba46-10f313f82cd8
STIX ID: report--39b82d9e-a2c1-5d25-ba46-10f313f82cd8
Feed Name: The Hacker News
Trend Micro observed APT Water Hydra exploiting a Microsoft Defender SmartScreen bypass (CVE-2024-21412) in the wild to target financial market traders. The actor used chained .URL internet shortcut files and a WebDAV-hosted CMD inside a ZIP to evade Mark of the Web and drop a malicious installer (7z.msi) from a booby-trapped link on forex forums, ultimately installing the DarkMe trojan with C2 and download/execute capabilities; Microsoft issued a patch in the February Patch Tuesday update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
