DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw
by kitang - Monday July 22, 2024 at 09:50 AM
#1
DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw

Breaches and Incidents  March 15, 2024  Cyware Alerts - Hacker News


Threat Intelligence Management Series


In a mid-January observation, a DarkGate malware campaign was noted capitalizing on a recently patched security loophole within Microsoft Windows. This zero-day exploit utilized deceptive software installers to trap unsuspecting users.

More in detail

Trend Micro reported that users were enticed through PDFs containing Google DoubleClick Digital Marketing (DDM) open redirects.
These redirects directed unsuspecting victims to compromised websites hosting the Microsoft Windows SmartScreen bypass flaw (CVE-2024-21412) that led to the delivery of malicious Microsoft (MSI) installers.
These fake MSI masqueraded as legitimate software, including Apple iTunes, Notion, and NVIDIA, to trick users into downloading the DarkGate malware.

It’s worth noting that the flaw was previously exploited by the Water Hydra group to target financial traders with DarkMe malware. 

Fake software installers remain a potential threat

https://cyware-ent.s3.amazonaws.com/imag...075185.jpg

The development comes as ASEC and eSentire revealed that counterfeit installers for Adobe Reader, Notion, and Synaptics were being distributed via fake PDF files and seemingly legitimate websites to deploy information stealers like LummaC2 and the XRed backdoor.

Additionally, Sophos X-Ops analysts noted that the developers behind QBot tricked users into downloading a QBot variant masquerading as an installer for an Adobe product.

Conclusion

Users are urged to apply the required security patches to stay safe from such attacks. Moreover, they must avoid downloading installers for legitimate software from unknown sources or via links embedded in the email. Organizations must get an understanding of IOCs associated with the campaign to block the threat at the initial stage.

source: https://cyware.com/news/darkgate-campaign-leverages-windows-smartscreen-bypass-flaw-77934b29
Reply
#2
I was waiting for someone to take advantage of this

Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [HOT] CVE-2026-41940: cPanel/WHM Auth Bypass to ROOT - 0-Day Chain Breakdown & PoC Zfruussia 1 218 Yesterday, 02:43 PM
Last Post: mimihack
  New Security Breach Allegations for Samsung TVs (Europe/UK Region) Tr28 0 149 Yesterday, 12:01 PM
Last Post: Tr28
  BreachForums Leak Free Data KingJulien 178 13,309 Apr 29, 2026, 10:25 AM
Last Post: HidanG
  News: Pitney Bowes Breached. dai5 0 176 Apr 29, 2026, 08:43 AM
Last Post: dai5
  PDF Exploit Builder by TheStrain – worth it? xXTH3_R3DXx 0 196 Apr 29, 2026, 03:28 AM
Last Post: xXTH3_R3DXx

Forum Jump:


 Users browsing this forum: 1 Guest(s)