• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
darkgate malware exploits recently patched microsoft flaw in zero day attack

DarkGate Malware Exploits Recently Patched Microsoft Flaw in Zero-Day Attack

You are here: Home / General Cyber Security News / DarkGate Malware Exploits Recently Patched Microsoft Flaw in Zero-Day Attack
March 14, 2024

A DarkGate malware marketing campaign observed in mid-January 2024 leveraged a lately patched security flaw in Microsoft Windows as a zero-day using bogus application installers.

“Throughout this campaign, consumers had been lured employing PDFs that contained Google DoubleClick Electronic Advertising and marketing (DDM) open up redirects that led unsuspecting victims to compromised web-sites hosting the Microsoft Windows SmartScreen bypass CVE-2024-21412 that led to destructive Microsoft (.MSI) installers,” Development Micro claimed.

CVE-2024-21412 (CVSS score: 8.1) problems an internet shortcut documents security feature bypass vulnerability that permits an unauthenticated attacker to circumvent SmartScreen protections by tricking a sufferer into clicking on a specially crafted file.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


It was mounted by Microsoft as element of its Patch Tuesday updates for February 2024, but not just before it was weaponized by a threat actor termed H2o Hydra (aka DarkCasino) to provide the DarkMe malware in attacks targeting monetary institutions.

The newest conclusions from Pattern Micro show that the vulnerability has arrive less than broader exploitation than earlier thought, with the DarkGate marketing campaign leveraging it in conjunction with open up redirects from Google Adverts to proliferate the malware.

Cybersecurity

The subtle attack chain begins with victims clicking on a link embedded in just a PDF attachment sent through a phishing email. The url deploys an open up redirect from Google’s doubleclick[.]net area to a compromised web server hosting a malicious .URL internet shortcut file that exploits CVE-2024-21412.

Especially, the open redirects are made to distribute pretend Microsoft software package installers (.MSI) masquerading as authentic computer software, such as Apple iTunes, Idea, NVIDIA, which arrive equipped with a side-loaded DLL file that decrypted and contaminated buyers with DarkGate (edition 6.1.7).

It is well worth noting that another now-set bypass flaw in Windows SmartScreen (CVE-2023-36025, CVSS rating: 8.8) has been employed by threat actors to supply DarkGate, Phemedrone Stealer, and Mispadu in excess of the past couple months.

The abuse of Google Ads technologies enables threat actors to raise the achieve and scale of their attacks by way of different advertisement strategies that are personalized for specific audiences.

“Employing fake software program installers, together with open redirects, is a potent combination and can direct to many bacterial infections,” security scientists Peter Girnus, Aliakbar Zahravi, and Simon Zuckerbraun reported. “It is necessary to continue to be vigilant and to instruct people not to have faith in any program installer that they get outside of official channels.”

Microsoft Flaw in Zero-Day Attack

The progress comes as the AhnLab Security Intelligence Heart (ASEC) and eSentire uncovered that counterfeit installers for Adobe Reader, Notion and Synaptics are remaining dispersed via bogus PDF documents and seemingly authentic internet websites to deploy details stealers like LummaC2 and the XRed backdoor.

It also follows the discovery of new stealer malware families like Planet Stealer, Rage Stealer (aka xStealer), and Tweaks (aka Tweaker), adding to the plethora of cyber threats that are capable of harvesting sensitive information from compromised hosts.

“Attackers are exploiting common platforms, like YouTube and Discord, to distribute Tweaks to Roblox end users, capitalizing on the potential of genuine platforms to evade detection by web filter block lists that usually block recognized destructive servers,” Zscaler ThreatLabz explained.

“Attackers share malicious files disguised as Frames For each Second (FPS) optimization offers with end users and, in convert, buyers infect their possess units with Tweaks malware.”

Cybersecurity

The PowerShell-dependent stealer is outfitted to exfiltrate sensitive details, which includes user facts, spot, Wi-Fi profiles, passwords, Roblox IDs, and in-sport forex particulars, to an attacker-managed server via a Discord webhook.

Malvertising and social engineering strategies have also been noticed acting as an original obtain vector to disseminate a wide array of stealer and distant access trojans like Agent Tesla, CyberGate RAT, Fenix botnet, Matanbuchus, NarniaRAT, Remcos RAT, Rhadamanthys, SapphireStealer, and zgRAT.

Located this post interesting? Observe us on Twitter  and LinkedIn to browse much more unique material we write-up.


Some parts of this report are sourced from:
thehackernews.com

Previous Post: «fortinet warns of severe sqli vulnerability in forticlientems software Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
Next Post: Ande Loader Malware Targets Manufacturing Sector in North America ande loader malware targets manufacturing sector in north america»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.