Temporary Advertisements:
Ad
Ad
Ad
DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw
by kitang - Monday July 22, 2024 at 09:50 AM
#1
DarkGate Campaign Leverages Windows SmartScreen Bypass Flaw

Breaches and Incidents  March 15, 2024  Cyware Alerts - Hacker News


Threat Intelligence Management Series


In a mid-January observation, a DarkGate malware campaign was noted capitalizing on a recently patched security loophole within Microsoft Windows. This zero-day exploit utilized deceptive software installers to trap unsuspecting users.

More in detail

Trend Micro reported that users were enticed through PDFs containing Google DoubleClick Digital Marketing (DDM) open redirects.
These redirects directed unsuspecting victims to compromised websites hosting the Microsoft Windows SmartScreen bypass flaw (CVE-2024-21412) that led to the delivery of malicious Microsoft (MSI) installers.
These fake MSI masqueraded as legitimate software, including Apple iTunes, Notion, and NVIDIA, to trick users into downloading the DarkGate malware.

It’s worth noting that the flaw was previously exploited by the Water Hydra group to target financial traders with DarkMe malware. 

Fake software installers remain a potential threat

https://cyware-ent.s3.amazonaws.com/imag...075185.jpg

The development comes as ASEC and eSentire revealed that counterfeit installers for Adobe Reader, Notion, and Synaptics were being distributed via fake PDF files and seemingly legitimate websites to deploy information stealers like LummaC2 and the XRed backdoor.

Additionally, Sophos X-Ops analysts noted that the developers behind QBot tricked users into downloading a QBot variant masquerading as an installer for an Adobe product.

Conclusion

Users are urged to apply the required security patches to stay safe from such attacks. Moreover, they must avoid downloading installers for legitimate software from unknown sources or via links embedded in the email. Organizations must get an understanding of IOCs associated with the campaign to block the threat at the initial stage.

source: https://cyware.com/news/darkgate-campaign-leverages-windows-smartscreen-bypass-flaw-77934b29
Reply
#2
I was waiting for someone to take advantage of this

Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 35 5,577 55 minutes ago
Last Post: agus123
  Breached forums and clones? fda5b 8 3,183 5 hours ago
Last Post: binaryplay
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 24 4,502 Yesterday, 04:17 PM
Last Post: krassimiryo
  Claude Mythos biyukean 7 1,104 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 20,121 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz

Forum Jump:


 Users browsing this forum: