New Mispadu Banking Trojan Exploiting Windows SmartScreen Flaw
ID: a9d63fd4-b47e-57a2-af67-6eb3dbca11a6
STIX ID: report--a9d63fd4-b47e-57a2-af67-6eb3dbca11a6
Feed Name: The Hacker News
Palo Alto Networks Unit 42 warns that operators of the Mispadu banking Trojan are exploiting a patched Windows SmartScreen bypass (CVE-2023-36025) by distributing crafted .URL internet shortcut files inside bogus ZIP attachments via phishing to compromise users in Mexico and LATAM; the malware selectively targets victims, contacts a C2 server for data exfiltration, and this vulnerability has also been abused by multiple cybercrime groups to deliver additional info-stealers, RATs, and loaders such as DarkGate, Phemedrone Stealer and DICELOADER.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
