Tag

Phemedrone

All articles tagged with #phemedrone

cybersecurity2 years ago

"Windows SmartScreen Vulnerability Exploited to Deliver Phemedrone Malware and Information Stealer"

A new information-stealing malware called Phemedrone is exploiting a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass Windows security prompts and harvest data from web browsers, cryptocurrency wallets, and various software applications. The flaw, fixed during November 2023 Patch Tuesday, allows attackers to trick victims into opening malicious URL files, leading to the execution of a PowerShell loader and the theft of sensitive information. Trend Micro reports that Phemedrone targets a wide range of applications and data, and has published indicators of compromise for this campaign.