Jump to content
  • Sign Up
×
×
  • Create New...

Patched Microsoft Defender flaw still being used to deliver information-stealing malware to vulnerable machines


Recommended Posts

  • Diamond Member

This is the hidden content, please

Patched
This is the hidden content, please
Defender flaw still being used to deliver information-stealing malware to vulnerable machines

data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///ywAAAAAAQABAAACAUwAOw==

A high-severity vulnerability in

This is the hidden content, please
Defender SmartScreen is being used to deliver information-stealing malware in Spain, Thailand, and the U.S., security researchers say. The researchers discovered the stealer campaign using ******-trapped files to exploit the vulnerability and deliver information stealers such as ACR Stealer, Lumma, and Meduza.

Fortinet FortiGuard Labs observed the latest stealer campaign spreading multiple files that can sidestep

This is the hidden content, please
Defender’s SmartScreen to download malicious software to target computers. The security vulnerability was addressed in CVE-2024-21412.

Since

This is the hidden content, please
closed this security ***** with an update released in February 2024, the news underscores the importance of installing security updates promptly. The disclosure comes on the heels of the CrowdStrike outage, which is also being leveraged to deliver malware:
This is the hidden content, please
that threat actors are delivering a fake recovery manual that delivers a previously undocumented stealer called Daolpu.

Security researcher Cara Lin said (

This is the hidden content, please
The Hacker News) that the attackers “lure victims into clicking a crafted link to a URL file designed to download an LNK file.” Once downloaded and opened, the LNK file downloads an executable file containing an HTML Application (HTA) script.

Next, the HTA decodes and decrypts obfuscated PowerShell code that retrieves decoy PDF files along with a shell code injector. This shell code injector then deploys and launches the malicious software. The malware transmits information from web browsers, crypto wallets, messaging apps, FTP and email clients, VPN services, and password managers through a ***** drop resolver on the Steam community website, a popular gaming service.

ACR Stealer targets a wide variety of popular applications. These include multiple versions of

This is the hidden content, please
Chrome, Epic Privacy Browser, Vivaldi,
This is the hidden content, please
Edge, Opera, and Mozilla Firefox, to name a few. It also targets messenger apps including Telegram, Pidgin, Signal, Tox, Psi, Psi+, and WhatsApp, along with numerous FTP clients.

VPN services NordVPN and AzireVPN have also been targeted, as have password managers Bitwarden, NordPass, 1Password, and RoboForm. While the hijacked data from a password manager should be encrypted, there ******** some risk of sensitive data being pulled from them. Fortinet has a complete list of known targeted software in its

This is the hidden content, please
.

Again, the

This is the hidden content, please
Defender SmartScreen vulnerability was patched in a February 2024 security update. However, if an organization doesn’t install such updates regularly, it ******** vulnerable to the threat.



This is the hidden content, please

#Patched #

This is the hidden content, please
#Defender #flaw #deliver #informationstealing #malware #vulnerable #machines

This is the hidden content, please

This is the hidden content, please

For verified travel tips and real support, visit: https://hopzone.eu/

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Vote for the server

    To vote for this server you must login.

    Jim Carrey Flirting GIF

  • Recently Browsing   0 members

    • No registered users viewing this page.

Important Information

Privacy Notice: We utilize cookies to optimize your browsing experience and analyze website traffic. By consenting, you acknowledge and agree to our Cookie Policy, ensuring your privacy preferences are respected.