Magniber Ransomware Exploits Windows SmartScreen Bypass Vulnerability
Picus Security has identified that the Magniber ransomware group is exploiting CVE-2023-24880. This vulnerability allows attackers to bypass Windows SmartScreen protections.

Cybersecurity firm Picus Security has reported that the Magniber ransomware group is actively exploiting a security vulnerability, CVE-2023-24880. This flaw affects Windows SmartScreen and enables attackers to bypass the "Mark of the Web" designation, hindering endpoint protection.
The vulnerability, disclosed by Microsoft, impacts Windows 10, Windows 11, and Windows Server 2016 and later. Google TAG researchers have linked this exploit to the distribution of Magniber ransomware. Picus Labs has added attack simulations for Magniber ransomware to its threat library.
Magniber ransomware, first detected in late 2017, has evolved over time. It has previously been observed masquerading as Windows update files and exploiting prior SmartScreen bypass vulnerabilities, such as CVE-2022-44698, using JavaScript.
The CVE-2023-24880 vulnerability stems from a prior SmartScreen bypass issue, specifically within the DoSafeOpenPromptForShellExec function of the shdocvw.dll module. When a SmartScreen request encounters an error while parsing a file's signature, the function can proceed to execute the file without user warning. While Microsoft patched previous vulnerabilities, this new exploit appears to circumvent those fixes.