Threat Advisory

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma and Meduza Stealer

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It is a critical security bypass vulnerability in Microsoft Windows SmartScreen. This flaw allows attackers to circumvent the SmartScreen security warning, potentially leading to the execution of malicious files on an affected system. The vulnerability can be exploited through a series of sophisticated techniques involving multiple malware frameworks, including ACR, Lumma, and Meduza Stealers, which enhance the attacker's ability to execute and conceal their malicious activities.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It is a critical security bypass vulnerability in Microsoft Windows SmartScreen. This flaw allows attackers to circumvent the SmartScreen security warning, potentially leading to the execution of malicious files on an affected system. The vulnerability can be exploited through a series of sophisticated techniques involving multiple malware frameworks, including ACR, Lumma, and Meduza Stealers, which enhance the attacker's ability to execute and conceal their malicious activities.[emaillocker id="1283"]

 

The exploitation of CVE-2024-21412 involves a multi-stage attack process. Initially, attackers craft a URL that directs the victim to a malicious link file (LNK). This LNK file then triggers the download of an executable containing a hidden HTA script. The script is designed to decode and execute PowerShell commands, which subsequently retrieve additional payloads. These payloads often include various types of stealers such as ACR, Lumma, and Meduza. Each of these stealers is used to gather sensitive information from the victim's system and exfiltrate it to a command and control server. The use of these advanced malware tools not only facilitates the initial infection but also helps in maintaining persistence and evading detection by employing various obfuscation techniques.

 

In conclusion, this CVE-2024-21412 poses a severe security risk due to its ability to bypass Windows SmartScreen's protective mechanisms. The advanced attack techniques, particularly the use of ACR, Lumma, and Meduza stealers, highlight the evolving strategies of threat actors. It is imperative for organizations and individuals to promptly apply security patches and adopt robust security practices to defend against potential exploitation of this vulnerability.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1203 Exploitation for Client Execution
T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
 Privilege Escalation T1068 Exploitation for Privilege Escalation
Credential Access T1003 OS Credential Dumping
Command and Control  T1071 Application Layer Protocol
 Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1485 Data Destruction

RECOMMENDATION:

We strongly recommend applying an update for Internet Shortcut Files Security Feature Bypass Vulnerability

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/07/microsoft-defender-flaw-exploited-to.html

[/emaillocker]
crossmenu