Windows SmartScreen flaw exploited to drop Phemedrone malware

Discussion in 'malware problems & news' started by waking, Jan 17, 2024.

  1. waking

    waking Registered Member

    Joined:
    Jan 25, 2016
    Posts:
    176
    Windows SmartScreen flaw exploited to drop Phemedrone malware

    January 15, 2024

    https://www.bleepingcomputer.com/ne...en-flaw-exploited-to-drop-phemedrone-malware/

    "A Phemedrone information-stealing malware campaign exploits a Microsoft Defender
    SmartScreen vulnerability (CVE-2023-36025) to bypass Windows security prompts when
    opening URL files."



    CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign

    January 12, 2024

    https://www.trendmicro.com/en_ae/re...-for-defense-evasion-in-phemedrone-steal.html

    "During routine threat hunting, Trend Micro uncovered evidence pointing to an
    active exploitation of CVE-2023-36025 to infect users with a previously unknown
    strain of the malware, Phemedrone Stealer."


    "Phemedrone targets web browsers and data from cryptocurrency wallets and messaging
    apps such as Telegram, Steam, and Discord. It also takes screenshots and gathers
    system information regarding hardware, location, and operating system details. The
    stolen data is then sent to the attackers via Telegram or their command-and-control
    (C&C) server. This open-source stealer is written in C# and is actively maintained
    on GitHub and Telegram."


    ...

    "Despite having been patched, threat actors continue to find ways to exploit
    CVE-2023-36025 and evade Windows Defender SmartScreen protections to infect
    users with a plethora of malware types, including ransomware and stealers
    like Phemedrone Stealer."
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Yes read about it. But what they sadly enough don't explain is if it can also bypass Win Defender? And they also don't explain why the built-in Windows firewall can't block it with default settings.
     
  3. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    I would assume anything that can bypass SmartScreen would bypass Defender as well. I would think they use the same definitions/rules. And a default Windows Firewall isn't going to stop you from clicking any link or downloading any file. And it doesn't stop outbound traffic.
     
  4. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    Shouldn't "The Microsoft Defender flaw exploited in the Phemedrone campaign is CVE-2023-36025, which was fixed during the November 2023 Patch Tuesday...." mean that if you did get infected your windows wasn't up to date? Or did the CVE-2023-36025 patch not worked as intended?
     
    Last edited: Jan 17, 2024
  5. Bertazzoni

    Bertazzoni Registered Member

    Joined:
    Apr 13, 2018
    Posts:
    745
    Location:
    Milan, Italia
    That would be a faulty assumption as MS Defender relies primarily on cloud-based protection with machine learning, AI, etc.
    https://learn.microsoft.com/en-us/m...rosoft-defender-antivirus?view=o365-worldwide
     
  6. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,145
    Location:
    USA
    Ok, then both of them fail individually.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Yes, I'm not so sure about this, because SmartScreen is basically a simple whitelist based on reputation from what I understood. But in this case it's likely that Win Defender was bypassed anyway, since it can't always spot infostealers. Win Defender depends too much on the cloud. And what I meant is, why doesn't MS beef up the built-in firewall? They could easily make a whitelist for trusted apps. And powershell.exe shouldn't be one of the trusted processes, obviously.

    Yes, I believe this is fixed.
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,648
    Location:
    U.S.A.
    Refer to the first posting in this thread; namely;
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.