Normal view

Received — 11 January 2026 ClearSky Cyber Security

CVE-2024-43451: A New Zero-Day Vulnerability Exploited in the wild

13 November 2024 at 18:56

A new zero-day vulnerability, CVE-2024-43451, was discovered by ClearSky Cyber Security in June 2024. This vulnerability affects Windows systems and is being actively exploited in attacks against Ukrainian entities.

The vulnerability activates URL files containing malicious code through seemingly innocuous actions:

  • A single right-click on the file (all Windows versions).
  • Deleting the file (Windows 10/11).
  • Dragging the file to another folder (Windows 10/11 and some Windows 7/8/8.1 configurations).

The malicious URL files were disguised as academic certificates and were initially observed being distributed from a compromised official Ukrainian government website.

Exploitation Process:

The attack begins with a phishing email sent from a compromised Ukrainian government server. The email prompts the recipient to renew their academic certificate. The email contains a malicious URL file. When the user interacts with the URL file by right-clicking, deleting, or moving it, the vulnerability is triggered. This action establishes a connection with the attacker’s server and downloads further malicious files, including SparkRAT malware.

SparkRAT is an open-source remote access trojan that allows the attacker to gain control of the victim’s system. The attackers also employed techniques to maintain persistence on the infected system, ensuring their access even after a reboot.

Attribution:

CERT-UA linked this campaign to the threat actor UAC-0194, suspected to be Russian. ClearSky also noted similarities with previous campaigns by other threat actors, suggesting the use of a common toolkit or technique.

Remediation:

Microsoft released a security patch for this vulnerability on November 12, 2024. Users are strongly advised to update their Windows systems to mitigate the risk posed by CVE-2024-43451.

Read the full report:

Doppelgänger NG | Russian Cyberwarfare campaign

22 February 2024 at 14:00

ClearSky Cyber Security and SentinelLabs have discovered a new wave of Russian information warfare campaign named Doppelgänger NG. “Doppelgänger” (meaning spirit double, an exact but usually invisible replica) is a global information warfare campaign publishing false information on hundreds of fake websites and social media channels.
Our research revealed that “Doppelgänger NG” is again fully operational in 2024, using new infrastructure. Furthermore, we found a link between the “Doppelgänger NG” Campaign and the Russian cyber espionage group APT28.

Key findings:

  • New infrastructure used by “Doppelgänger NG”.
  • We discovered a potential link between APT28 to “Doppelgänger NG” campaign.
  • The “Doppelgänger NG” campaign has expanded its victims list, including new targets in the US, Germany, Israel, and France.
  • The “Doppelgänger NG” network contains more than 150 domains, including news feeds
    relevant to five countries (United State, Israel, France, Germany, Ukraine).

Doppelgänger report

Doppelgänger IoCs file

SentinelLabs report

❌