logo

DarkMe Malware Targets Traders Using Microsoft SmartScreen Zero-Day Vulnerability

ID: 39b82d9e-a2c1-5d25-ba46-10f313f82cd8

STIX ID: report--39b82d9e-a2c1-5d25-ba46-10f313f82cd8

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-02-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Trend Micro observed APT Water Hydra exploiting a Microsoft Defender SmartScreen bypass (CVE-2024-21412) in the wild to target financial market traders. The actor used chained .URL internet shortcut files and a WebDAV-hosted CMD inside a ZIP to evade Mark of the Web and drop a malicious installer (7z.msi) from a booby-trapped link on forex forums, ultimately installing the DarkMe trojan with C2 and download/execute capabilities; Microsoft issued a patch in the February Patch Tuesday update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.