DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw
by kitang - Monday July 22, 2024 at 09:50 AM
#1
DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw

Breaches and Incidents  March 15, 2024  Cyware Alerts - Hacker News


Threat Intelligence Management Series


In a mid-January observation, a DarkGate malware campaign was noted capitalizing on a recently patched security loophole within Microsoft Windows. This zero-day exploit utilized deceptive software installers to trap unsuspecting users.

More in detail

Trend Micro reported that users were enticed through PDFs containing Google DoubleClick Digital Marketing (DDM) open redirects.
These redirects directed unsuspecting victims to compromised websites hosting the Microsoft Windows SmartScreen bypass flaw (CVE-2024-21412) that led to the delivery of malicious Microsoft (MSI) installers.
These fake MSI masqueraded as legitimate software, including Apple iTunes, Notion, and NVIDIA, to trick users into downloading the DarkGate malware.

It’s worth noting that the flaw was previously exploited by the Water Hydra group to target financial traders with DarkMe malware. 

Fake software installers remain a potential threat

[Image: 46bc_shutterstock_680075185.jpg]

The development comes as ASEC and eSentire revealed that counterfeit installers for Adobe Reader, Notion, and Synaptics were being distributed via fake PDF files and seemingly legitimate websites to deploy information stealers like LummaC2 and the XRed backdoor.

Additionally, Sophos X-Ops analysts noted that the developers behind QBot tricked users into downloading a QBot variant masquerading as an installer for an Adobe product.

Conclusion

Users are urged to apply the required security patches to stay safe from such attacks. Moreover, they must avoid downloading installers for legitimate software from unknown sources or via links embedded in the email. Organizations must get an understanding of IOCs associated with the campaign to block the threat at the initial stage.

source: https://cyware.com/news/darkgate-campaign-leverages-windows-smartscreen-bypass-flaw-77934b29
Reply
#2
I was waiting for someone to take advantage of this

Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Malicious VSCode extensions infect Windows with cryptominers lulagain 0 279 04-07-2025, 10:25 PM
Last Post: lulagain
  Max severity RCE flaw discovered in widely used Apache Parquet lulagain 2 307 04-07-2025, 10:59 AM
Last Post: CardoSoldier
  Verizon Call Filter API flaw exposed customers' incoming call history lulagain 0 246 04-03-2025, 07:41 AM
Last Post: lulagain
  Critical RCE flaw in Apache Tomcat actively exploited in attacks lulagain 0 297 03-18-2025, 03:21 PM
Last Post: lulagain
  New SuperBlack ransomware exploits Fortinet auth bypass flaws lulagain 0 344 03-14-2025, 10:20 PM
Last Post: lulagain

Forum Jump:


 Users browsing this thread: 1 Guest(s)