Microsoft Defender SmartScreen bug exploited to spread info-stealers

Microsoft Defender SmartScreen bug exploited to spread info-stealers

A recently patched security vulnerability in Microsoft Defender SmartScreen has been actively exploited in a sophisticated campaign designed to deliver a range of information stealers, including ACR Stealer, Lumma, and Meduza.

The campaign, observed by FortiGuard Labs, leverages the flaw (CVE-2024-21412) to download malicious executable files. This is a security restrictions bypass issue that allows attackers to bypass SmartScreen protection and deliver malicious payloads. Microsoft addressed this vulnerability in its February 2024 monthly security updates.

The attackers initiate the process by enticing victims to click on a crafted link to a URL file, which then downloads an LNK file. This LNK file subsequently downloads an executable containing an HTML Application (HTA) script.

Once executed, the script decodes and decrypts PowerShell code to fetch the final URLs, decoy PDF files, and a malicious shellcode injector. The final stealer is then injected into legitimate processes, initiating malicious activities and sending the stolen data to a command-and-control (C2) server.

FortiGuard Labs has detected this campaign targeting users in North America, Spain, and Thailand. The threat actors have developed different injectors to evade detection and utilize various PDF files to specifically target these regions, the company said.

Back to the list

Latest Posts

Cyber Security Week in Review: June 13, 2025

Cyber Security Week in Review: June 13, 2025

In brief: Microsoft fixes zero-day exploited by the Stealth Falcon APT, the Graphite spyware targets journalists via an iMessage exploit, and more.
13 June 2025
Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

The campaign, first observed on June 5, involves brute-force login attempts originating from hundreds of unique IP addresses.
12 June 2025
ConnectWise rotates digital certificates due to security risks

ConnectWise rotates digital certificates due to security risks

The company said that this is a preventive action and not related to any recent security incident.
11 June 2025