Implementing Latest Security Updates Crucial Against New CVE-2024-21412 Threat

24 Jul 2024

The attack chain begins with an initial phishing email containing a malicious link. Upon clicking the link, a URL file is downloaded, which subsequently downloads an LNK file. This LNK file executes PowerShell commands to download an HTA script disguised as an overlay icon.

LNK File Execution and Payload Decoding

The HTA script decodes and executes a hidden PowerShell script that runs silently in the background. This script downloads a decoy PDF and a malicious shell code injector, which then injects the final stealer into legitimate processes. Two types of injectors have been identified in this campaign. The first injector uses an image file to obtain shell code, maintaining low detection rates on VirusTotal. The second injector downloads a JPG file from the Imghippo website and uses the Windows API “GdipBitmapGetPixel” to access pixels and decode bytes to retrieve the shell code. This second injector is more straightforward, decrypting its code from the data section and utilizing a series of Windows API functions to perform shell code injection.

Stealer Deployment and Regional Targeting

Once the code is injected, it downloads and installs information-stealing malware such as Meduza Stealer version 2.9 or ACR Stealer. The ACR Stealer targets various applications, including browsers, crypto wallets, messengers, FTP clients, email clients, VPN services, password managers, and other tools. It can adapt legitimate web services to maintain communications with its C2 server. The campaign appears to target specific regions, with decoy PDFs tailored to North America, Spain, and Thailand.

Implementing Microsoft’s latest security updates to address the CVE-2024-21412 vulnerability is crucial for protection. Users should be cautious of phishing links and downloading unknown files. Email security solutions can detect and block phishing attempts, while a comprehensive security suite can provide real-time malware protection.

Mr. Ngoc Bui, Cybersecurity Expert at Menlo Security, commented on the recent development stating, “The recent discovery of CVE-2024-21412 reveals the persistent and evolving nature of cyber threats targeting Microsoft’s SmartScreen. It demonstrates that attackers are constantly refining their tactics to bypass traditional security measures and deliver malicious payloads to high-value targets. This highlights the need for proactive threat intelligence and layered defenses to protect against these sophisticated attacks.”

RELATED TOPICS

  • Windows Defender Flaw Exploited by Phemedrone Stealer
  • Critical New Outlook RCE Vulnerability Exploits Preview Pane
  • 7-Year-Old 0-Day in MS Office Exploited to Drop Cobalt Strike
  • Black Basta Ransomware Exploited Windows 0-day Before Patch
  • Palo Alto Patches 0-Day (CVE-2024-3400) Exploited by Backdoor
  • MS Outlook Vulnerability Exploited by Russian Forest Blizzard Group
  • Microsoft Releases Tool to Fix CrowdStrike-Caused Windows Chaos
  • Russian APT28 Exploiting Windows Vulnerability with GooseEgg Tool
uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4909803
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
818232
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
417188
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
299877
downloads

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more