ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Exploitation of CVE-2023-36025 Unveils Phemedrone Stealer Malware

Kyle by Kyle
January 16, 2024 - Updated on January 18, 2024
in Malware
Reading Time: 3 mins read
Phemedrone Stealer Unleashes Advanced Tactics: Second Stage Extraction, Exfiltration Mastery, and Persistent Exploitation Despite CVE Patch.
Share on FacebookShare on Twitter

Cybersecurity experts have recently exposed a significant threat to digital security, revealing the active exploitation of CVE-2023-36025. This exploitation has allowed the emergence of a new and potent strain of malware named Phemedrone Stealer.

Phemedrone Stealer’s Targets and Data Collection

This malware is designed with a specific focus on web browsers, aiming to extract sensitive information from cryptocurrency wallets and popular messaging applications like Telegram, Steam, and Discord.

  • Explicit targeting of web browsers
  • Data collection from cryptocurrency wallets and messaging apps

Furthermore, Phemedrone is adept at gathering comprehensive system information, including hardware details and location. The stolen data is then discreetly transmitted to the attackers through the encrypted channels of Telegram or their command-and-control (C2) server.

Vulnerability Impacting Windows Defender SmartScreen

The root cause of this security breach lies in a vulnerability affecting Microsoft Windows Defender SmartScreen. This vulnerability stems from inadequate checks on Internet Shortcut (.url) files.

  • Impact on Windows Defender SmartScreen
  • Inadequate checks on Internet Shortcut (.url) files

Threat actors exploit this vulnerability by creating .url files capable of downloading and executing malicious scripts, effectively bypassing Windows Defender SmartScreen warnings.

Microsoft’s Response and CISA Inclusion

Microsoft took action to address this vulnerability on November 14, 2023. Despite this, the exploitation in the wild prompted the Cybersecurity and Infrastructure Security Agency (CISA) to promptly include it in the Known Exploited Vulnerabilities (KEV) list on the same day.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

  • Microsoft’s response on November 14, 2023
  • CISA’s inclusion in the Known Exploited Vulnerabilities (KEV) list

Evidence indicates that since its discovery, various malware campaigns, including those distributing the Phemedrone Stealer payload, have incorporated this vulnerability into their attack chains.

Attack Vector and Evasion Techniques

The primary attack vector involves hosting malicious .url files on cloud services such as Discord or FileTransfer.io. Attackers employ URL shorteners to disguise these files effectively.

  • Hosting on cloud services like Discord
  • Use of URL shorteners for disguise

Once the malicious .url file exploiting CVE-2023-36025 is executed, Phemedrone employs advanced defense evasion techniques, including DLL sideloading and dynamic API resolving, to obfuscate its presence. Persistence is achieved through the creation of scheduled tasks and the utilization of an encrypted second-stage loader.

The unfolding saga of the Phemedrone Stealer takes a more intricate turn in its second stage, deploying an open-source shellcode named Donut. This strategic move empowers the malware to execute various file types directly in the volatile realm of computer memory.

Dynamics of Targeting and Information Extraction

This malware exhibits dynamic targeting capabilities, honing in on a diverse array of applications and services. The extraction process is not limited; it delves into browsers, cryptocurrency wallets, and platforms such as Discord, FileZilla, and Steam.

  • Utilization of open-source shellcode Donut
  • Execution of various file types in memory
  • Dynamic targeting of a broad range of applications and services

During this phase, Phemedrone Stealer adeptly extracts sensitive information, including credentials crucial for its malevolent agenda.

Data Exfiltration Mastery

The malware showcases sophistication in its data exfiltration process, employing an elaborate method to compress and transmit the harvested data. The chosen conduit for this operation is the Telegram API, ensuring both efficiency and stealth.

  • Compression of harvested data
  • Transmission through the Telegram API
  • Validation of Telegram API token for data integrity
  • Detailed system information report sent to attackers

This meticulous approach not only safeguards the integrity of the transmitted data but also provides the attackers with a comprehensive system information report, enriching their understanding of the compromised system.

Persistent Exploitation Despite Patch

Despite Microsoft’s efforts in issuing a patch for CVE-2023-36025, the threat landscape remains grim. Trend Micro reports that threat actors persist in exploiting this vulnerability, underscoring the urgency for organizations to take swift action.

“Organizations must prioritize updating Microsoft Windows installations to thwart exposure to the Microsoft Windows Defender SmartScreen Bypass,” emphasizes the advisory.

“The existence of public proof-of-concept exploit code on the web elevates the risk for organizations lagging behind in adopting the latest patched version.”

Tags: Stealer
Previous Post

Bosch Thermostats Vulnerable to Remote Vulnerability

Next Post

Critical Security Vulnerabilities in Rapid SCADA Expose Industrial Systems

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.