Threat actors exploited CVE-2023-36025, a Microsoft Windows Defender SmartScreen bypass vulnerability, to deliver the Phemedrone Stealer through malicious .url Internet Shortcut files hosted on services including Discord and FileTransfer.io. The infection chain downloaded a .cpl payload, abused control.exe and rundll32.exe to evade defenses, then retrieved additional PowerShell stages and a ZIP archive from GitHub. Microsoft patched the flaw in November 2023, and CISA later added it to the Known Exploited Vulnerabilities (KEV) catalog after in-the-wild abuse was confirmed.
The malware established persistence through DLL sideloading and a scheduled task, decrypted a second-stage loader from an RC4-encrypted file, and used the Donut in-memory loader to run the final .NET stealer payload. Phemedrone collected browser credentials, cryptocurrency wallet files, Discord and Telegram data, FileZilla credentials, Steam-related files, screenshots, and detailed host information, then validated and exfiltrated the stolen data primarily through the Telegram API. The campaign also aligned with MITRE ATT&CK T1218.002, reflecting the use of signed Windows binaries such as control.exe for system binary proxy execution.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft patched CVE-2023-36025, a Windows Defender SmartScreen bypass vulnerability involving insufficient checks and prompts on Internet Shortcut (.url) files. The flaw was later linked to malware delivery in the wild.
Trend Micro published research detailing how the campaign abused control.exe, rundll32.exe, PowerShell, GitHub-hosted stages, RC4 decryption, and the Donut in-memory loader to execute Phemedrone. The report also described data theft targets and exfiltration through the Telegram API.
Trend Micro documented an active campaign in which attackers used malicious .url files hosted on services including Discord and FileTransfer.io to exploit CVE-2023-36025 and bypass SmartScreen protections. The infection chain led to staged payload downloads, persistence via DLL sideloading and a scheduled task, and final deployment of the Phemedrone Stealer malware.
CISA added CVE-2023-36025 to its Known Exploited Vulnerabilities catalog based on evidence of in-the-wild exploitation. The reference does not provide a specific date for this action.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.