Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Australia Charges Four Over $123M Crypto Money Laundering Ring

June 13, 2025

Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

June 13, 2025

World’s largest financial clearinghouse DTCC eyeing stablecoin launch

June 13, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Could 3AC and Terraform be Blamed for Singapore’s Crackdown on Offshore Crypto Firms?

    June 13, 2025

    A New Security Device For A New Generation

    June 13, 2025

    Bitcoin Bull Run Incoming as BTC CAGR Hits 31%

    June 13, 2025

    BlackRock Bitcoin Fund Flies Past $70,000,000,000 Faster Than Any Other ETF in History: Bloomberg Analyst

    June 12, 2025

    Crypto Trader Michaël van de Poppe Says Bitcoin on Cusp of Breakout, Updates Outlook on Ethereum and Bittensor

    June 13, 2025

    Ethereum whale buy 16.5k ETH worth $46.4 million

    June 13, 2025

    Crypto Analyst Says New Bitcoin All-Time Highs Incoming, Updates Outlook on Ethereum

    June 13, 2025

    Ethereum beats S&P 500 and Solana—Here’s what the $65B DeFi war signals!

    June 12, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    Bitcoin Funding Rate Flips Again And History Says A Rally Is Around The Corner

    June 13, 2025

    Bitrue hacker buys Ethereum as ETH sees $393 mln outflow: Bullish signs?

    June 13, 2025

    Best Crypto Meme Presale Coins to Unlock Big Gains

    June 12, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025
  • DeFi

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025

    Crypto is near a ‘tipping point,’ FSB chair warns

    June 13, 2025

    DeFi Dev Corp secures $5b to expand Solana holdings

    June 13, 2025

    Alchemy Pay partners with Backed to launch first direct fiat access to tokenized stocks and ETFs

    June 12, 2025

    Ukraine advances crypto reserve mission with strategic bill

    June 12, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    SEC vs Ripple Case: Parties Seek Ruling to Dissolve Injunction, Release $125M Civil Penalty

    June 13, 2025

    REI Network and VitaminAI Partner to Build Scalable Infrastructure for AI Agents

    June 13, 2025

    Hong Kong Customs Teams with HKU to Trace Crypto Transactions

    June 13, 2025

    Solana-based golf rewards app GolfN hits App Store

    June 13, 2025

    Coinbase data breach spills offline as victims get scam mail

    June 6, 2025

    Cryptojacking Campaign Targets DevOps Servers Including Nomad

    June 3, 2025

    Sophisticated Malware Campaign Targets Windows and Linux Systems

    June 2, 2025

    US Treasury sanctions Philippines tech firm over aiding $200 million pig butchering spree

    May 31, 2025

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    FIFA Rivals Mobile Game Debuts Worldwide with PvP Action and Digital Ownership

    June 13, 2025

    Boston Entrepreneurs Launch Abodio, an AI-Powered Platform That is Transforming Homeownership

    June 13, 2025

    Privacy Defender Advances Digital Privacy Solutions for Public Figures & Influencers

    June 12, 2025

    Solana hitting 1M TPS, memecoin rug pull seizures to put SOL on US digital asset stockpile radar

    June 12, 2025

    Off The Grid active wallets hold steady ahead of Steam launch

    June 13, 2025

    Tencent exploring $15B Nexon acquisition, a gaming firm with Web3 investments

    June 13, 2025

    My Neighbor Alice teases new Pudgy Penguins Web3 game

    June 12, 2025

    My Neighbor Alice Unveils Cross-Chain NFT Integration with Pudgy Penguins

    June 12, 2025

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethiopia prepares to regulate crypto despite ongoing ban

    June 13, 2025

    SEC, Ripple seek to end multi-year legal dispute with amended filing

    June 13, 2025

    Congress Unveils Major U.S Crypto Regulation Bill Update

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Shopify to enable USDC payments via Base across its Checkout ecosystem

    June 13, 2025

    Hong Kong teams up with university to tackle crypto laundering with tech

    June 13, 2025

    Just 216 Bitcoin holders own over 6 million BTC as market concentration grows

    June 12, 2025

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025
  • Analysis

    Will WLD Price Hit $10?

    June 13, 2025

    Wells Fargo Issues Massively Bearish Tesla (TSLA) Price Target Despite Highly-Anticipated Robotaxi Launch: Report

    June 13, 2025

    Top Reasons Why Bitcoin Price Will Rebound and Explode To New ATH Before End of June

    June 13, 2025

    Citigroup Braces for Loan Losses, Sets Aside Hundreds of Millions of Dollars for Potential Downturn Amid Tough Macro Environment: Report

    June 12, 2025

    Is this a Calm of Maturity or Just the Eye Before the Next Storm?

    June 12, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    Coinbase to launch CFTC-cleared perpetual futures trading, Bitcoin-backed credit card for US customers

    June 13, 2025

    FTX continues to exclude Nigeria and China in remaining creditor repayments but includes Payoneer

    June 12, 2025

    BiT Global drops Coinbase lawsuit over wrapped Bitcoin delisting

    June 10, 2025

    Coinbase CEO says unnecessary account restrictions has reduced by 82%

    June 8, 2025

    Australia Charges Four Over $123M Crypto Money Laundering Ring

    June 13, 2025

    Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

    June 13, 2025

    World’s largest financial clearinghouse DTCC eyeing stablecoin launch

    June 13, 2025

    Tony G Buys $438K in Hyperliquid Tokens—Is $HYPE the Next Sol Strategies Play?

    June 13, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»Phemedrone Stealer Targets Windows Defender Flaw Despite Patch
Phemedrone Stealer Targets Windows Defender Flaw Despite Patch
Security and Privacy

Phemedrone Stealer Targets Windows Defender Flaw Despite Patch

December 15, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity experts have recently discovered the exploitation of a critical vulnerability, CVE-2023-36025, leading to the emergence of a new strain of malware known as Phemedrone Stealer. This malicious software specifically targets web browsers and collects sensitive data from cryptocurrency wallets and messaging applications like Telegram, Steam, and Discord. Moreover, Phemedrone Stealer gathers system information, including hardware details and location, sending the stolen data to the attackers through Telegram or their command-and-control (C2) server.

The vulnerability affecting Microsoft Windows Defender SmartScreen arises from insufficient checks on Internet Shortcut (.url) files. Threat actors take advantage of this loophole by creating .url files that download and execute malicious scripts, bypassing Windows Defender SmartScreen warnings. Although Microsoft addressed this vulnerability on November 14, 2023, its exploitation in the wild prompted the Cybersecurity and Infrastructure Security Agency (CISA) to include it in the Known Exploited Vulnerabilities (KEV) list on the same day.

Since its discovery, evidence suggests that various malware campaigns, including those distributing the Phemedrone Stealer payload, have incorporated this vulnerability into their attack chains. Attackers typically host malicious .url files on cloud services like Discord or FileTransfer.io, using URL shorteners to mask these files.

When the malicious .url file exploiting CVE-2023-36025 is executed, the malware employs defense evasion techniques such as DLL sideloading and dynamic API resolving to conceal its presence. The malware establishes persistence by creating scheduled tasks and utilizes an encrypted second-stage loader.

Phemedrone Stealer’s second stage involves the use of an open-source shellcode called Donut, enabling the execution of various file types in memory. The malware dynamically targets a wide range of applications and services to extract sensitive information, including credentials, from browsers, crypto wallets, Discord, FileZilla, Steam, and more.

See also  Atari to Drop Exclusive Patch Packs on Blockchain Marketplace DYLI With a Nostalgic Twist

Furthermore, the malware employs a sophisticated data exfiltration process, compressing and sending the harvested data through the Telegram API. It ensures data integrity by validating the Telegram API token and transmits a detailed system information report to the attackers.

Despite Microsoft releasing a patch for CVE-2023-36025, threat actors continue to exploit this vulnerability, underscoring the importance for organizations to promptly update their Windows installations. Trend Micro emphasizes the critical need for organizations to update their Microsoft Windows installations to prevent exposure to the Microsoft Windows Defender SmartScreen Bypass. Public proof-of-concept exploit code is available on the web, increasing the risk for organizations that have not yet updated to the latest patched version.

Stay informed and vigilant in protecting your systems against these evolving cyber threats.

Defender Flaw Patch Phemedrone Stealer Targets Windows
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Privacy Defender Advances Digital Privacy Solutions for Public Figures & Influencers

June 12, 2025

Coinbase data breach spills offline as victims get scam mail

June 6, 2025

Cryptojacking Campaign Targets DevOps Servers Including Nomad

June 3, 2025

Sophisticated Malware Campaign Targets Windows and Linux Systems

June 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

YGG Launches New Publishing Arm, Debuts First Game ‘LOL Land’

May 23, 2025

Global Petcare IoT Platforms Market Forecasted to Grow at 17.9% CAGR, Reaching $24.72 Billion by 2030.

January 2, 2025

Ethereum (ETH) Price Prediction For February 25

February 26, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Australia Charges Four Over $123M Crypto Money Laundering Ring

June 13, 2025

Ethereum’s sharp 15% fall: Is this a classic bull trap in play?

June 13, 2025

World’s largest financial clearinghouse DTCC eyeing stablecoin launch

June 13, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.