Security News Windows Zero-Day Exploited in Targeted Attacks by 'PowerPool' Group

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Aug 17, 2014
12,746
123,919
8,399
A threat group tracked by security firm ESET as “PowerPool” has been exploiting a Windows zero-day vulnerability to elevate the privileges of a backdoor in targeted attacks.
According to ESET, the local privilege escalation vulnerability has been exploited by a newly uncovered group it tracks as PowerPool. Based on the security firm’s telemetry and malware samples uploaded to VirusTotal, the threat actor appears to have leveraged the Windows zero-day against a small number of users located in the United States, the United Kingdom, Germany, Ukraine, Chile, India, Russia, the Philippines and Poland
 
Last edited:
What do you guys think about using 0patch?
I am not worried about this exploit.
1 It will never even get started on a default/deny setup.
2 The analysts say the remotely controlled backdoor that it installs is probably only used against hand-picked targets.