A malicious campaign distributing the Phemedrone info-stealer malware exploits a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass security alerts Windows when opening URL files.

Phemedrone is a new information-stealing malware. It collects data stored in browsers, crypto wallets, and software like Discord, Steam, and Telegram. The stolen data is sent to the attackers and can be used for other malicious activities or sold on a hacking forum.
The Microsoft Defender vulnerability used to distribute the Phemedrone malware is tracked as CVE-2023-36025. It was fixed by Microsoft on Patch Tuesday November 2023.
See also: Windows 11: The new features coming in 2024
According to the company, the victim's device is compromised as follows: the user clicks on a specially crafted Internet Shortcut (.URL) or a hyperlink that leads to an Internet Shortcut file.
Although the vulnerability had begun to be used in attacks, Microsoft initially did not provide many details. However, proof-of-concept exploits, increasing the risk to Windows systems that had not applied the updates.
Trend Micro says that Phemedrone wasn't the only malware that exploited this Windows vulnerability. Ransomware.
Bypassing Microsoft Defender SmartScreen
Initially, attackers services cloud like Discord and FireTransfer.io and often hide them using shortening services like shorturl.at.
Typically, when opening URL files downloaded from the internet or sent via email, Windows SmartScreen displays a warning about the risks that opening the file may pose to the device.
However users , open the malicious files without the warning appearing. And so the command is executed automatically. in this case, which exploits the CVE-2023-36095 vulnerability in Windows SmartScreen,

The URL file then downloads a control panel item (.cpl) file from the attacker's control server and executes it, launching a malicious DLL payload via rundll32.exe.
See also: Microsoft: Windows 10 WinRE update with BitLocker fixes
The DLL is a PowerShell loader that retrieves a ZIP from a GitHub repository. It contains the second-stage loader disguised as a PDF (Secure.pdf), a legitimate Windows binary (WerFaultSecure.exe), and “wer.dll.” The latter is used for DLL side-loading and to establish persistence.
Once launched on the compromised system, the Phemedrone malware decrypts the necessary assets and steals data, using Telegram to extract data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Trend Micro reports that Phemedrone targets the following applications/data:
- Chromium browsers: Collects passwords, cookies, and autofill from browsers and security apps like LastPass, KeePass, Microsoft Authenticator, and Google Authenticator.
- Gecko Browsers: Steals user data from Gecko-based browsers, such as Firefox.
- Crypto wallets: Extracts data from various crypto wallet applications (e.g. Atom, Armory, Electrum, and Exodus).
- Discord: Gains unauthorized access by extracting authentication tokens.
- System Information: Collects data related to hardware, geographic location, operating system details, and screenshots.
- FileGrabber: Collects user files from folders such as Documents and Desktop.
- FileZilla: Records FTP details and credentials.
- Steam: Has access to files related to the platform.
- Telegram: Extracts user data, focusing on authentication files in the “tdata” folder.
General risks of exploiting the vulnerability
The first risk that arises from exploiting the SmartScreen bug is the possibility of installing malware on the computer (as is already the case with the Phemedrone malware).
See also: Windows 10: Security update KB5034441 has bugs
Additionally, exploiting the vulnerability could lead to a breach of user privacy . Malware could track user activity, steal personal information, such as passwords and credit card details, and transfer it to third parties.
Finally, this issue could lead to a loss of trust from users in the Windows operating system and Microsoft's security technologies. This could have significant implications for the company, as users may decide to switch to other platforms.
Source: www.bleepingcomputer.com
