HomeSecurityHackers exploit vulnerability in Microsoft Defender to spread ACR, Lumma and...

Hackers Exploit Microsoft Defender Vulnerability to Spread ACR, Lumma, and Meduza Stealers

A vulnerability in Microsoft Defender SmartScreen, which has now been patched, was exploited by a new malicious campaign that aims to install info-stealers such as ACR Stealer, Lumma, and Meduza.

Microsoft Defender

According to Fortinet FortiGuard Labs, this campaign targeted Spain, Thailand, and the US, using malicious code files that exploited the CVE-2024-21412 vulnerability (CVSS score: 8.1).

This vulnerability allows hackers to bypass SmartScreen protection and execute malicious payloads. Microsoft fixed the issue as part of the February 2024 monthly security updates.

See also: Cisco: Vulnerability allows adding root users to SEG devices

"First, hackers trick victims into clicking on a modified URL link, which is designed to download an LNK file," said security researcher Cara Lin. "The LNK file then downloads an executable file containing an [HTML Application] script."

The HTA file acts as a conduit for decoding and decrypting PowerShell code, which retrieves a PDF file and an injection code. It then installs either Meduza Stealer or Hijack Loader, which in turn launches ACR Stealer or Lumma.

ACR Stealer, an advanced version of GrMsk Stealer, appeared in late March 2024 by a threat actor named SheldIO on the Russian-speaking underground forum RAMP.

“ACR Stealer uses a DDR technique to evade detection by hiding its command and control on the Steam community website,” Lin noted, highlighting its ability to collect information from web programs, crypto wallets, messaging apps, FTP clients, email clients, VPN services, and password managers.

It is worth noting that recent Lumma Stealer attacks have been observed using the same technique, allowing hackers to change C2 domains at any time and make the infrastructure more resilient, according to AhnLab Security Intelligence Center (ASEC).

This update was released after CrowdStrike revealed that threat actors were exploiting the recent outage to distribute an old info-stealer, called Daolpu, that had not been documented, highlighting the ongoing impact of the faulty update that has disabled millions of Windows.

The attack involves the use of a Microsoft Word document with macros, disguised as a Microsoft recovery manual, containing legitimate instructions for resolving the issue. The document is used as bait to trigger the infection process.

When the DOCM file is opened, a macro is executed that retrieves a second-stage DLL file from a remote server, which then executes Daolpu, a malware designed to collect credentials and cookies from Google Chrome, Microsoft Edge, Mozilla Firefox, and other Chromium-based browsers.

Microsoft Defender

The emergence of new families malware , such as Braodo and DeerStealer, combined with malicious advertising techniques that promote legitimate software, such as Microsoft Teams, to develop Atomic Stealer.

Read also: Critical vulnerability in Apache HugeGraph – Update ASAP!

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“As cybercriminals intensify their distribution campaigns, it becomes more risky to download applications via search engines,” said Malwarebytes researcher Jérôme Segura. “Users must navigate between bad advertising (sponsored results) and SEO poisoning (hacked websites).”.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS