Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • How to decide which one chooses
    • Tarangy National Park: The hidden jewel of Tanzania
    • 15 Something to do around Chautauqua Lake, New York – a short drive from Buffalo, Cleveland, or Pitsburgh
    • Discover the magic of relaxation and rich history of hot springs, Arkansas: a perfect mix of nature and culture
    • Level8 Creator Carry -A – Best Luggage for Modern Travel
    • The area revolves around: an exciting and friendly way to try Atlanta
    • 15 things I hope to know before visiting the ball in Las Vegas
    • Summer 2022, sixth week – practical life laboratory from Robin Camarriot
    Facebook X (Twitter) Instagram
    ZEMS BLOG
    • Home
    • Sports
    • Reel
    • Worklife
    • Travel
    • Future
    • Culture
    • Politics
    • Weather
    • Financial Market
    • Crypto
    ZEMS BLOG
    Home » Hackers are weaponizing a Windows flaw to spread Phemedrone Stealer encryption
    Crypto

    Hackers are weaponizing a Windows flaw to spread Phemedrone Stealer encryption

    ZEMS BLOGBy ZEMS BLOGJanuary 16, 2024No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    January 16, 2024newsroomCryptocurrency/Windows Security

    Crypto-Retract Phemedrone Stealer

    Threat actors have been observed taking advantage of a now-patched vulnerability in the Microsoft Windows operating system to deploy an open source information theft tool called Phemidron is a thief.

    “Phemedrone targets web browsers and data from cryptocurrency wallets and messaging apps like Telegram, Steam, and Discord,” said Trend Micro researchers Peter Girnos, Aliakbar Zohrafi, and Simon Zuckerbraun.

    “It also takes screenshots and collects system information related to hardware, location, and operating system details. The stolen data is then sent to the attackers via Telegram or their command and control (C&C) server.”

    The attacks leverage CVE-2023-36025 (CVSS Score: 8.8), a security bypass vulnerability in Windows SmartScreen, which can be exploited by tricking a user into clicking on a specially crafted Internet shortcut (.URL) or hyperlink pointing to the Internet. Shortcut file.

    Cyber ​​security

    The actively exploited flaw has been addressed by Microsoft as part of the November 2023 Patch Tuesday updates.

    The infection process involves the threat actor hosting malicious Internet Shortcut files on Discord or cloud services like FileTransfer.io, while also obscuring links using URL shorteners like Short URL.

    Executing the booby-trapped .URL file allows it to connect to an actor-controlled server and execute a Control Panel (.CPL) file in a way that circumvents Windows Defender SmartScreen by leveraging CVE-2023-36025.

    “When the malicious .CPL file is executed by the binary process in Windows Control Panel, it in turn calls rundll32.exe to execute the DLL file,” the researchers said. “This malicious DLL file acts as a loader that then calls Windows PowerShell to download and execute the next stage of the attack, hosted on GitHub.”

    The afterload is a PowerShell loader (“DATA3.txt”) that acts as a launchpad for Donut, an open source shellcode loader that decrypts and executes Phemedrone Stealer.

    Cyber ​​security

    Phemedrone Stealer, written in C#, is actively maintained by its developers on GitHub and Telegram, making it easier to steal sensitive information from compromised systems.

    This development is once again a sign that threat actors are becoming more agile and quickly adapting their attack chains to take advantage of newly disclosed vulnerabilities and inflict maximum damage.

    “Despite being patched, threat actors continue to find ways to exploit CVE-2023-36025 and evade Windows Defender SmartScreen protection to infect users with a wide number of types of malware, including ransomware and hijackers like Phemedrone Stealer,” the researchers said.

    Found this article interesting? Follow us Twitter  And LinkedIn to read more of our exclusive content.



    Source link

    ZEMS BLOG
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRacist Christian Bashir Joy Reed criticizes Iowa's predominantly white Christian demographics in party participation (video) | Critic portal
    Next Article S&P 500 futures fall as Treasury yields rise and traders eye profits
    ZEMS BLOG
    • Website

    Related Posts

    A security engineer was imprisoned for 3 years for hacking cryptocurrencies worth $12 million

    April 12, 2024

    6 Common Risks in Self-Directed IRAs and Bitcoin Checkbooks

    April 12, 2024

    Asset tokenization, artificial intelligence attracts focus from IOSCO Fintech team

    April 12, 2024
    Leave A Reply Cancel Reply

    How to decide which one chooses

    May 9, 2025

    Tarangy National Park: The hidden jewel of Tanzania

    May 2, 2025

    15 Something to do around Chautauqua Lake, New York – a short drive from Buffalo, Cleveland, or Pitsburgh

    April 22, 2025

    Discover the magic of relaxation and rich history of hot springs, Arkansas: a perfect mix of nature and culture

    April 21, 2025
    Recent Posts
    • How to decide which one chooses
    • Tarangy National Park: The hidden jewel of Tanzania
    • 15 Something to do around Chautauqua Lake, New York – a short drive from Buffalo, Cleveland, or Pitsburgh
    • Discover the magic of relaxation and rich history of hot springs, Arkansas: a perfect mix of nature and culture
    • Level8 Creator Carry -A – Best Luggage for Modern Travel
    About

    ZEMS BLOG in partnership with Holiday Omega keeps you informed. Bringing you the latest news from around the world with fresh perspectives and unique insights. Your daily source for news from around the world. All perspectives, all curated for a global audience.

    Facebook X (Twitter) Instagram YouTube Telegram
    • About Us
    • Contact Us
    • Privacy Policy
    • Disclaimer
    Subscribe For latest updates

    Type above and press Enter to search. Press Esc to cancel.