Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Russian Hackers Use New NTLM Flaw to Deploy RAT Malware via Phishing Emails
Global Security

Russian Hackers Use New NTLM Flaw to Deploy RAT Malware via Phishing Emails

AdminBy AdminNovember 14, 2024No Comments3 Mins Read
RAT Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 14, 2024Ravi LakshmananMalware / Vulnerability

RAT malware

A recently patched security flaw affecting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russian-linked actor in cyberattacks against Ukraine.

The vulnerability in question, CVE-2024-43451 (CVSS score: 6.5), is an NTLM hash disclosure spoofing vulnerability that can be exploited to steal a user’s NTLMv2 hash. It was patched up from Microsoft earlier this week.

“Minimal user interaction with a malicious file, such as selecting (single-click), inspecting (right-clicking), or performing actions other than opening or executing, could trigger this vulnerability,” Microsoft said in its advisory.

Cyber ​​security

Israeli cybersecurity firm ClearSky, which discovered exploits of the June 2024 zero-day flaw, said it has been abused as part of a chain of attacks that provide open source code Spark RAT malware.

“The vulnerability activates URL files that lead to malicious activity,” the company said, adding that the malicious files were hosted on an official Ukrainian government website that allows users to download academic certificates.

The chain of attacks involves sending phishing emails from a compromised Ukrainian government server (“doc.osvita-kp.gov(.)ua”) that prompts recipients to restore their academic credentials by clicking on a mined URL embedded in the message.

This results in the download of a ZIP archive containing a malicious Internet Shortcut (.URL) file. The vulnerability is triggered when a victim interacts with a URL file by right-clicking, deleting, or dragging it to another folder.

RAT malware

The URL file is for establishing connections to a remote server (“92.42.96(.)30”) to download additional payloads, including the Spark RAT.

“Additionally, executing the sandbox caused a warning about an attempt to transfer the NTLM (NT LAN Manager) hash over the SMB (Server Message Block) protocol,” ClearSky said. “Once the NTLM Hash is obtained, an attacker can perform a Pass-the-Hash attack to identify himself as the user associated with the captured hash without having to enter the corresponding password.”

Ukraine’s Computer Emergency Response Team (CERT-UA) linked the activity to a likely Russian threat it is tracking as UAC-0194.

Cyber ​​security

In recent weeks, the agency also warned that tax-related phishing emails were being used to distribute legitimate remote desktop software called LiteManager, describing the attack campaign as financially motivated and launched by a threat called UAC-0050.

“Accountants of enterprises whose computers work with remote banking systems are in a special risk zone,” CERT-UA warned. “In individual cases, as evidenced by the results of computer forensic studies, from the moment of the primary attack to the moment of the theft of funds, no more than an hour can pass.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.