Fake LDAPNightmare exploit on GitHub spreads infostealer malware
Briefly

The malicious GitHub repository appears to come from SafeBreach Labs' legitimate PoC for CVE-2024-49113, showing how threat actors exploit trust.
This particular case highlights the persistent tactic where malicious tools masquerade as PoC exploits on GitHub, tricking users into malware infection.
Upon downloading from the malicious repository, victims receive a UPX-packed executable that schedules an encrypted script to collect sensitive information.
The misleading PoC exploit exemplifies how attackers manipulate interest around vulnerabilities to distract and ensnare unsuspecting users.
Read at Techzine Global
[
|
]