New Malware Bypasses Windows SmartScreen, Threatening User Data

cve 2022 44698

A recently uncovered malware campaign, leveraging a flaw in Windows Defender SmartScreen, is causing alarm in the cybersecurity world. This new malware, known as Phemedrone Stealer, is exploiting the CVE-2023-36025 vulnerability to infiltrate systems and steal a wide range of user data.

Key Highlights:

  • A new malware strain, Phemedrone Stealer, exploits a vulnerability in Microsoft Defender SmartScreen (CVE-2023-36025).
  • Phemedrone is an open-source info-stealer targeting data in web browsers, cryptocurrency wallets, and various software.
  • The malware can gather extensive information including system details, files, passwords, and sensitive data from browsers and applications.
  • Attackers use .url files hosted on trusted cloud services to trick users, bypassing SmartScreen warnings.
  • The vulnerability was patched by Microsoft in November 2023, but continues to be exploited in attacks.

cve 2022 44698

Phemedrone Stealer, an open-source information-stealing malware, is particularly dangerous due to its ability to harvest data from various sources, including web browsers, cryptocurrency wallets, and software like Discord, Steam, and Telegram. This malware can extract extensive information, such as hardware and operating system details, geolocation, system screenshots, user files, browser cookies, passwords, and authentication tokens. Notably, it targets Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, Brave, etc.) and Gecko-based browsers (e.g., Firefox), as well as password and authenticator apps, Discord, Steam, Telegram, and cryptocurrency wallet apps. The stolen data is then compressed and exfiltrated via the Telegram API.

The exploit begins when a victim is tricked into opening a malicious .url file hosted on trusted cloud services like Discord or FireTransfer.io. This file, often disguised using URL shortener services, downloads and executes a control panel item (.cpl) file from the attacker’s server. This file launches a PowerShell loader, which then fetches a ZIP file containing the second-stage loader and other components essential for establishing persistence and carrying out the attack.

This vulnerability in Windows Defender SmartScreen was patched by Microsoft in November 2023. However, it remains a significant threat due to the continued exploitation of unpatched systems and the circulation of proof-of-concept exploits on social media.

The Threat Landscape

Bypassing SmartScreen

The exploitation of the CVE-2023-36025 flaw allows attackers to bypass Windows Defender SmartScreen checks and warnings. This results in the victim unknowingly executing the malware without any prompt from Windows about the potential danger.

Impact and Defense

The comprehensive data theft capabilities of Phemedrone Stealer highlight the need for robust cybersecurity measures. Users are advised to ensure their systems are updated with the latest security patches to mitigate the risk of such attacks. Additionally, being cautious about downloading and opening files from unknown sources is crucial.

Broader Implications in Cybersecurity

The emergence of Phemedrone Stealer is a significant event in the cybersecurity landscape, highlighting the continuous evolution of cyber threats. It serves as a reminder of the importance of staying ahead of threat actors by adopting proactive and comprehensive cybersecurity strategies. The exploitation of vulnerabilities like CVE-2023-36025 also underscores the need for software developers and vendors to be vigilant in identifying and patching vulnerabilities promptly.

The Phemedrone Stealer campaign is a stark reminder of the evolving cybersecurity threats and the importance of timely software updates and vigilance. Despite Microsoft’s patch for the CVE-2023-36025 vulnerability, the ongoing exploitation of this flaw underscores the need for continuous monitoring and updating of cybersecurity defenses.

About the author

James

James Miller

James is the Senior Writer & Rumors Analyst at PC-Tablet.com, bringing over 6 years of experience in tech journalism. With a postgraduate degree in Biotechnology, he merges his scientific knowledge with a strong passion for technology. James oversees the office staff writers, ensuring they are updated with the latest tech developments and trends. Though quiet by nature, he is an avid Lacrosse player and a dedicated analyst of tech rumors. His experience and expertise make him a vital asset to the team, contributing to the site’s cutting-edge content.

Web Stories

5 Best Projectors in 2024: Top Long Throw and Laser Projectors for Every Budget 5 Best Laptop of 2024 5 Best Gaming Phones in Sept 2024: Motorola Edge Plus, iPhone 15 Pro Max & More! 6 Best Football Games of all time: from Pro Evolution Soccer to Football Manager 5 Best Lightweight Laptops for High School and College Students 5 Best Bluetooth Speaker in 2024 6 Best Android Phones Under $100 in 2024 6 Best Wireless Earbuds for 2024: Find Your Perfect Pair for Crystal-Clear Audio Best Macbook Air Deals on 13 & 15-inch Models Start from $149