Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Engrypthub exploits Windows Zero-Day to deploy rhadamanthys and Sharealc Marsware
Global Security

Engrypthub exploits Windows Zero-Day to deploy rhadamanthys and Sharealc Marsware

AdminBy AdminMarch 26, 2025No Comments3 Mins Read
Windows Zero-Day
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 26, 2025Red LakshmananSecurity / vulnerability Windows

Zero day Windows

Actor threats known as Encryption Exploits the recently concurrent security vulnerability in Microsoft Windows as a zero day to provide a wide range of malware families, including back and information theft such as Rhadamanthys and Ctealc.

“In this attack, the actor threatens .Msc files and multilingual – Note In the analysis.

Vulnerability in questionMmc) This can allow the attacker to bypass the security function at the local level. It was fixed The company earlier this month as patch update on Tuesday.

Cybersecurity

Trend Micro gave a feat nickname MSC Eviltwin, tracking the suspected Russian cluster of activity called Water Gamayun. Actor threats recently the subject of the analyzes Inspects and Outpost24 are also called larva-208.

The CVE-2025-26633, according to its basis, uses the Microsoft Management Framework Console (MMC) to perform the malicious Microsoft console (.MSC) using PowerShell loading MSC Eviltwin Loader.

In particular, it provides for the creation of two .MSC names of the same name: one pure file and its analogue of the robbers, which is dropped in the same place but in the catalog called “en-US”. The idea is that when previously launched, MMC unintentions selects the malicious file and performs it. This is performed by using the MMC Multilingual Multilingual Interface (Muipath).

Zero day Windows

“By abusing the way MMC.exe uses Muipath, the attacker can equip Muipath En-US. The .MMSC, which causes MMC.exe to download this malicious file instead of the original file and executed without the victim,”-explained.

It was also noted that when taking the other two methods to run the malicious load in the infected system using .MMSC files –

  • Use ExecuCteshellcommand MMC method to download and perform a useful load on the victim’s car, approach Previously documented Dutch cybersecurity campaign in August 2024
  • With the help of Bulled trusted catalogs For example, “C: \ Windows \ System32” (note the blank blank) to bypass the user account (UAC) and give up
Cybersecurity

Trend Micro noted that the attack chains are probably starting with the Files Digitally Microsoft Installer Microsoft (MSI) boot, representing themselves to a legitimate Chinese software, such as Dingtalk or QQtalk, which is then used to obtain and perform a remote server loader. The actor is said to have the threat experimenting with these methods since April 2024.

“This company is under active development; it uses several delivery methods and custom useful loads designed to maintain persistence and theft of sensitive data, and then allocate it to command and control from the attackers (C&C),” said the stuck.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025

Coinbase agents are bribed, data ~ 1% of users were traced; Attempted extortion of $ 20 million will not succeed

May 15, 2025

NPM malicious package uses Unicode Steganography, Google Calendar as C2 Chroper

May 15, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.