The computer security software company Trend Micro released the news that a vulnerability (CVE-2023-36025) allowed Phemedrone Stealer to infect users' devices by simply clicking on a malicious link.
Phemedrone is recognised as a malware skilled in data theft, targeting a wide range of applications and services in order to exfiltrate sensitive information.
Despite Microsoft having fixed this vulnerability in November last year, threat actors continue to use this exploit in their attack chains on systems that have not been updated.
While Trend Micro's report focuses on the Phemedrone infection chain, our report concentrates on the technical analysis of CVE-2023-36025 and how these exploits can be detected by pattern identification.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/