DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw
by kitang - Monday July 22, 2024 at 09:50 AM
#1
DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw

Breaches and Incidents  March 15, 2024  Cyware Alerts - Hacker News


Threat Intelligence Management Series


In a mid-January observation, a DarkGate malware campaign was noted capitalizing on a recently patched security loophole within Microsoft Windows. This zero-day exploit utilized deceptive software installers to trap unsuspecting users.

More in detail

Trend Micro reported that users were enticed through PDFs containing Google DoubleClick Digital Marketing (DDM) open redirects.
These redirects directed unsuspecting victims to compromised websites hosting the Microsoft Windows SmartScreen bypass flaw (CVE-2024-21412) that led to the delivery of malicious Microsoft (MSI) installers.
These fake MSI masqueraded as legitimate software, including Apple iTunes, Notion, and NVIDIA, to trick users into downloading the DarkGate malware.

It’s worth noting that the flaw was previously exploited by the Water Hydra group to target financial traders with DarkMe malware. 

Fake software installers remain a potential threat

https://cyware-ent.s3.amazonaws.com/imag...075185.jpg

The development comes as ASEC and eSentire revealed that counterfeit installers for Adobe Reader, Notion, and Synaptics were being distributed via fake PDF files and seemingly legitimate websites to deploy information stealers like LummaC2 and the XRed backdoor.

Additionally, Sophos X-Ops analysts noted that the developers behind QBot tricked users into downloading a QBot variant masquerading as an installer for an Adobe product.

Conclusion

Users are urged to apply the required security patches to stay safe from such attacks. Moreover, they must avoid downloading installers for legitimate software from unknown sources or via links embedded in the email. Organizations must get an understanding of IOCs associated with the campaign to block the threat at the initial stage.

source: https://cyware.com/news/darkgate-campaign-leverages-windows-smartscreen-bypass-flaw-77934b29
Reply
#2
I was waiting for someone to take advantage of this

Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  claude ai omgijkl 0 11 7 minutes ago
Last Post: omgijkl
  NVIDIA confirms GeForce NOW data breach affecting Armenian users namenonamen 2 181 2 hours ago
Last Post: PhantomKernel
  Canvas login portals hacked in mass ShinyHunters extortion campaign namenonamen 3 280 5 hours ago
Last Post: phas3lock
  Gmail breach is real or not? dai5 5 512 May 08, 2026, 10:08 PM
Last Post: dai5
  Zara data breach exposed personal information of 197,000 people namenonamen 1 142 May 08, 2026, 07:22 PM
Last Post: darkbigfoot

Forum Jump:


 Users browsing this forum: 1 Guest(s)