logo

New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw

ID: a9d63fd4-b47e-57a2-af67-6eb3dbca11a6

STIX ID: report--a9d63fd4-b47e-57a2-af67-6eb3dbca11a6

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-02-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 warns that operators of the Mispadu banking Trojan are exploiting a patched Windows SmartScreen bypass (CVE-2023-36025) by distributing crafted .URL internet shortcut files inside bogus ZIP attachments via phishing to compromise users in Mexico and LATAM; the malware selectively targets victims, contacts a C2 server for data exfiltration, and this vulnerability has also been abused by multiple cybercrime groups to deliver additional info-stealers, RATs, and loaders such as DarkGate, Phemedrone Stealer and DICELOADER.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.