Site icon TheCyberThrone

Microsoft SmartScreen bug exploited in an infostealer campaign

Advertisements

Researchers have uncovered an info stealer campaign targeting Microsoft Windows users. This campaign exploits a known vulnerability to bypass security measures and steal sensitive data.

The vulnerability tracked as CVE-2024-21412 is a security bypass in Microsoft Windows SmartScreen. The flaw allows remote attackers to bypass the SmartScreen security warning dialogue and deliver malicious files.

Advertisements

Many attack campaigns, including Lumma Stealer and Meduza Stealer, have exploited this vulnerability in the past.

This campaign’s sequence of attacks.

The ACR Stealer targets various applications, including browsers, crypto wallets, messengers, FTP clients, email clients, VPN services, password managers, and other tools. The stealer can adapt legitimate web services to maintain communications with its C2 server.

The campaign seems to target specific regions, with decoy PDFs tailored to North America, Spain, and Thailand.

Advertisements

It is recommended to install latest security updates to address the CVE-2024-21412 vulnerability are crucial to stay protected.

Users should be cautious of phishing links and downloading unknown files. Email security solutions can detect and block phishing attempts.

This research was documented by researchers from Fortiguard labs.

Indicators of Compromise

Exit mobile version