HomeSecurityGitHub: Fake PoC exploit for vulnerability distributes infostealer

GitHub: Fake PoC exploit for infostealer vulnerability distributed

A fake proof-of-concept (PoC) exploit for the CVE-2024-49113 vulnerability (also known as “LDAPNightmare”) on GitHub is infecting users with infostealer malware. The malware steals sensitive data and sends it to an external FTP server.

PoC exploit vulnerability GitHub

This is not the first time we've seen malicious tools disguised as PoC exploits on GitHub to trick users.

This particular campaign was discovered by Trend Micro.

A deceptive PoC exploit on GitHub

Trend Micro reports that the malicious GitHub repository contains a project that appears to have elements in common with SafeBreach Labs' legitimate PoC for the CVE-2024-49113 vulnerability.

See also: Beware! New malware campaign distributes Skuld info-stealer

The vulnerability affects Windows Lightweight Directory Access Protocol (LDAP) and was patched by Microsoft with the December 2024 Patch Tuesday. At the same time, another vulnerability in LDAP, CVE-2024-49112, was also patched.

SafeBreach's initial post about the PoC exploit incorrectly reported the vulnerability as CVE-2024-49112, while the PoC was for CVE-2024-49113. This error, which was later corrected, created more interest around the LDAPNightmare vulnerability and its attack potential, which is what the attackers in this campaign likely attempted to exploit.

Users who download the PoC exploit from the malicious GitHub repository will receive a UPX-packed executable "poc.exe" which, upon execution, installs a PowerShell script in the victim's %Temp% folder.

The script creates a scheduled job on the compromised system, which executes a coded script that retrieves a third script from Pastebin. This final payload is the infostealer that collects computer information, process lists, directory lists, IP address, network adapter information, and installed updates. It uploads this information in a ZIP file format to an external FTP server.

See also: Hacker jailed for his involvement in Raccoon Stealer malware

A list of breach indicators is available in the Trend Micro report

GitHub users who download public exploits for research or testing should be careful and only use POC exploits from well-known cybersecurity companies and researchers.

On the other hand, cybercriminals may try to impersonate well-known researchers security, so validating the authenticity of the repository is also crucial.

If possible, the code should be checked before execution. It is a good idea to first upload the binaries to VirusTotal.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

infostealer LDAPNightmare

General tips for protecting against info-stealer malware

First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from these types of attacks.

Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.

See also: Hackers use RedLine Stealer to steal credentials

Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.

Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS