ZeroHour
Security Affairspublished ()ingested @securityaffairs

Phemedrone campaign exploits Windows smartScreen bypass

criticalThreat actorimportance 60CVE-2023-36025

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36025
Windows SmartScreen Bypass (CVE-2023-36025) Exploited via Crafted Shortcut Files

CVE-2023-36025 is a security feature bypass in Windows SmartScreen in which a specially crafted file — exploited in the wild using Internet Shortcut (.url) files — evades the Mark-of-the-Web warning SmartScreen normally displays for content downloaded from the internet. The flaw is network-reachable and requires no authentication, but user interaction is required: it triggers when a user clicks the crafted file delivered via phishing email, chat, or a web download. By bypassing the SmartScreen prompt, the attacker removes a key user-facing defense that would otherwise flag or warn about the file, which facilitated delivery of malware in the observed DarkGate and Mispadu campaigns. Any unpatched Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 system is affected, which at the time of disclosure effectively meant the entire supported Windows installed base. It is confirmed exploited in the wild: CISA added it to the KEV catalog on 2023-11-14, EPSS scores 30-day exploitation probability at 88.1% (100th percentile), though no public PoC is known.

Do: Apply Microsoft's November 2023 cumulative Windows security updates (the release containing the fix) on all affected Windows 10/11 and Windows Server systems; no configuration-based workaround is widely documented, so patching is the primary mitigation. Until patched, treat unexpected Internet Shortcut (.url) files arriving via email or chat with extra suspicion, since they can execute without the usual SmartScreen warning, and hunt for DarkGate/Mispadu indicators. Given the KEV listing and 88.1% EPSS, prioritize this fix in the current patch cycle; ransomware-associated use is reported as unknown.

8.888% KEV
  • microsoft Windows 10 1507 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1607 (builds prior to the November 2023 security updates)
  • microsoft Windows 10 1809 (builds prior to the November 2023 security updates)
  • +9 more
mass>1 billion endpoints (effectively the entire supported Windows 10/11/Server installed base at the time of disclosure)
Full article480 words · extracted from securityaffairs.com · click to collapse

Threat actors exploit a recent Windows SmartScreen bypass flaw CVE-2023-36025 to deliver the Phemedrone info stealer.

Trend Micro researchers uncovered a malware campaign exploiting the vulnerability CVE-2023-36025 (CVSS score 8.8) to deploy a previously unknown strain of the malware dubbed Phemedrone Stealer.

The vulnerability was addressed by Microsoft with the release of Patch Tuesday security updates for November 2023. The vulnerability is a Windows SmartScreen Security Feature Bypass issue.

An attacker can exploit this flaw to bypass Windows Defender SmartScreen checks and other prompts. This flaw can be exploited in phishing campaigns to evade user prompts that warn recipients about opening a malicious document.

After public disclosure of the vulnerability, multiple demos and proof-of-concept codes have been published on social media. Experts noticed that a growing number of malware campaigns have included the exploit for this flaw into their attack chains. 

Phemedrone Stealer allows operators to steal sensitive data from web browsers and cryptocurrency wallets and messaging apps such as Telegram, Steam, and Discord. The malware supports multuple capabilities, including taking screenshots and gathering system information regarding hardware, location, and operating system details.

The stolen data is exfiltrated via Telegram or their C2 server. The malware is written in C#, its authors actively maintain the malicious code on GitHub and Telegram. 

“Once the malicious .url file exploiting CVE-2023-36025 is executed, it connects to an attacker-controlled server to download and execute a control panel item (.cpl) file. Microsoft Windows Defender SmartScreen should warn users with a security prompt before executing the .url file from an untrusted source.” reads the report published by Trend Micro. “However, the attackers craft a Windows shortcut (.url) file to evade the SmartScreen protection prompt by employing a .cpl file as part of a malicious payload delivery mechanism.”

The malicious URL files exploiting CVE-2023-36025 reference Discord or other cloud services. Upon executing the files, a control panel item (.cpl) file is downloaded and executed. Then it calls rundll32.exe to execute a malicious DLL acting as a loader for the next stage, a malicious script hosted on GitHub.

The next stage is an obfuscated loader that fetches a ZIP archive from the same GitHub repository to a hidden directory created using the Windows attribute utility binary (attrib.exe).   

The archive contains the files to load the next stage and maintain persistence. The next stage loads the Phemedrone Stealer payload.

“Despite having been patched, threat actors continue to find ways to exploit CVE-2023-36025 and evade Windows Defender SmartScreen protections to infect users with a plethora of malware types, including ransomware and stealers like Phemedrone Stealer.” concludes the report.  “Malware strains such as Phemedrone Stealer highlight the evolving nature of sophisticated malware threats and malicious actors’ ability to quickly enhance their infection chains by adding new exploits for critical vulnerabilities in everyday software.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Phemedrone)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/157496/hacking/phemedrone-info-stealer-campaign-exploit-cve-2023-36025.html