A new Windows Defender zero-day is already being exploited to drop dangerous malware

microsoft, a new windows defender zero-day is already being exploited to drop dangerous malware

A new Windows Defender zero-day is already being exploited to drop dangerous malware

Hackers are exploiting a zero-day vulnerability in Windows Defender SmartScreen to infect crypto traders with malware.

Researchers from Trend Micro revealed a threat actor going by Water Hydra (AKA DarkCasino) abused the zero-day, now tracked as CVE-2024-21412, in attacks conducted on New Year’s Eve 2023.

Microsoft has since released a patch, and in a follow-up advisory, explained that an unauthenticated attacker “could send the targeted user a specially crafted file that is designed to bypass displayed security checks.”

Spearphishing on Telegram

Microsoft further explained that the attack still relies on victim action: “However, the attacker would have no way to force a user to view the attacker-controlled content. Instead, the attacker would have to convince them to take action by clicking on the file link.”

Trend Micro claims Water Hydra was joining Telegram channels and forums for forex, stock, and crypto traders, and used spearphishing techniques to get people to install the DarkMe malware. The group shared a stock chart that linked to fxbulls[.]ru, a compromised Russian trading information site that, in fact, impersonates fxbulls[.]com, a forex broker platform.

DarkMe, while dangerous on its own, was just a step towards the final goal, which was to deploy ransomware, the researchers claim.

“In late December 2023, we began tracking a campaign by the Water Hydra group that contained similar tools, tactics, and procedures (TTPs) that involved abusing internet shortcuts (.URL) and Web-based Distributed Authoring and Versioning (WebDAV) components,” Trend Micro explained.

“We concluded that calling a shortcut within another shortcut was sufficient to evade SmartScreen, which failed to properly apply Mark-of-the-Web (MotW), a critical Windows component that alerts users when opening or running files from an untrusted source.”

The crypto industry has always been a popular target for cybercriminals. However, with bitcoin exchange-traded funds (ETF) finally approved, and the Bitcoin halving just two months away, the crypto industry is poised for yet another eye-watering bull run. This, as was the case in the past, will also attract more criminals.

Via BleepingComputer

More from TechRadar Pro

    News Related

    OTHER NEWS

    Jimmy Carter and all living former first ladies to attend Rosalynn Carter’s memorial service

    Former President Jimmy Carter is expected to attend the Tuesday memorial service for his late wife, Rosalynn Carter, in Atlanta, his grandson told CNN – a tribute that will also be ... Read more »

    Rob Reiner to Film ‘This Is Spinal Tap' Sequel in February, Says Paul McCartney and Elton John Will Appear

    Rob Reiner to Film ‘This Is Spinal Tap’ Sequel in February, Says Paul McCartney and Elton John Will Appear Forty years after making his directorial debut with the 1984 cult ... Read more »

    Best Buy's Biggest Cyber Monday Deals on Samsung TVs, Sony Headphones, and Dyson Vacuums

    Plus laptops and more last-minute deals you don’t want to miss People / Jaclyn Mastropasqua We have reached Cyber Monday is officially here, and there are loads of great deals ... Read more »

    The Joffre Lakes surge returns north of Pemberton

    The Joffre Lakes surge is back, much to the dismay of Pemberton and Mount Currie locals. Video footage shared with Pique shows a long line of cars illegally parked on ... Read more »

    Activists calling for Gaza ceasefire begin hunger strike outside White House

    Photograph: Jim Watson/AFP/Getty Images Leftwing activists including the actor Cynthia Nixon, famous for her role in Sex and the City, have begun a hunger strike outside the White House aimed ... Read more »

    We just got a first look at McDonald's secretive new spinoff restaurant CosMc's

    A construction site in Bolingbrook, Illinois, presumed to be the first location of CosMc’s. Scott Fredrickson McDonald’s has been reluctant to share many details about its planned new restaurant concept ... Read more »

    Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening

    Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening Conor McGregor made around a $2 million investment when he purchased the Dublin bar he ... Read more »
    Top List in the World