{"id":55046,"date":"2024-01-12T00:00:00","date_gmt":"2024-01-12T00:00:00","guid":{"rendered":"urn:uuid:0e26baae-e3d4-336c-9d73-9f7ad0bb2d19"},"modified":"2024-01-12T00:00:00","modified_gmt":"2024-01-12T00:00:00","slug":"cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/","title":{"rendered":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/phemedrone-stealer-exploit:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/24\/phemedrone-stealer-exploit.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"34.5625\">\n<div readability=\"14.8125\">\n<p><span class=\"body-subhead-title\">Defense evasion by exploiting CVE-2023-36025<\/span><\/p>\n<p>Once the malicious .url file exploiting CVE-2023-36025 is executed, it connects to an attacker-controlled server to download and execute a control panel item (.cpl) file. Microsoft Windows Defender SmartScreen should warn users with a security prompt before executing the .url file from an untrusted source. However, the attackers craft a Windows shortcut (.url) file to evade the SmartScreen protection prompt by employing a .cpl file as part of a malicious payload delivery mechanism. Threat actors leverage MITRE ATT&amp;CK technique <a href=\"https:\/\/attack.mitre.org\/techniques\/T1218\/002\/\">T1218.002<\/a>, which abuses the Windows Control Panel process binary (<i>control.exe<\/i>) to execute .cpl files. Note that these files are DLL files.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>When the malicious .cpl file is executed through the Windows Control Panel process binary, it in turn calls <i>rundll32.exe<\/i> to execute the DLL.&nbsp;This malicious DLL acts as a loader that then calls on Windows PowerShell to download and execute the next stage of the attack, hosted on GitHub. The next stage is another PowerShell loader named <i>DATA3.txt<\/i>.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36.366463414634\">\n<div readability=\"17.934146341463\">\n<p>The file <i>DATA3.txt<\/i> is an additional obfuscated loader that uses PowerShell string and digit manipulation techniques to mask its contents and make deciphering its true purpose more difficult during static analysis<a>.&nbsp;<\/a><\/p>\n<p>Using a combination of static and dynamic analysis, we can deobfuscate the GitHub-hosted loader, which gives us a series of PowerShell commands that this script executes. This loader downloads a ZIP file hosted on the same GitHub repository to a hidden directory created using the Windows attribute utility binary (<i>attrib.exe<\/i>).&nbsp;&nbsp;&nbsp;<\/p>\n<p>The zip archive contains three files:&nbsp;&nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b><i>WerFaultSecure.exe.<\/i><\/b><i> <\/i><span>This is a legitimate Windows Fault Reporting binary.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b data-rte-class=\"rte-temp\"><b><i>Wer.dll.<\/i><\/b> <\/b><span>This is a malicious binary that is sideloaded when <i>WerFaultSecure.exe<\/i> is executed.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b><i>Secure.pdf.<\/i> <\/b><span>This is an RC4-encrypted second stage loader.&nbsp;<\/span><\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"38.5\">\n<div readability=\"22\">\n<p><span class=\"body-subhead-title\">Persistence using scheduled tasks and DLL sideloading<\/span><\/p>\n<p>The <i>wer.dll<\/i> file is a crucial component of the loader&#8217;s functionality as it decrypts and runs the second stage loader and achieves persistence by creating scheduled tasks that we will detail here. The malware utilizes multiple techniques to evade detection and complicate reverse engineering, such as API hashing and string encryption. Additionally, this DLL is packed and protected by VMProtect.&nbsp;&nbsp;<\/p>\n<p>The loader is executed using the DLL sideloading technique, where the attacker spoofs a malicious DLL file in the application&#8217;s directory. This tricks the operating system into loading the malicious file instead of the legitimate one. In the case we investigated, <i>WerFaultSecure.exe<\/i> executes the <i>WerpSetExitListeners<\/i> function from <i>wer.dll<\/i>, which triggers the loader to run.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p>The loader uses a technique called dynamic API resolving to hide its API imports and make it harder for static analysis. This technique involves storing the hashes of the necessary APIs instead of their names, and then importing them dynamically at runtime. In the case we investigated, the loader uses the Cyclic Redundancy Check 32 (CRC-32) hashing algorithm, contents of which are detailed in the following table.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\">\n<tbody>\n<tr>\n<td><i>998B531E<\/i><\/td>\n<td><i>KERNEL32.DLL&nbsp;&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>46DED02D<\/i><\/td>\n<td><i>GetModuleHandleExW&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0FC6B42F1<\/i><\/td>\n<td><i>GetModuleFileNameW<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0C97C1FFF<\/i><\/td>\n<td><i>GetProcAddress&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>3FC1BD8D<\/i><\/td>\n<td><i>LoadLibraryA&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0F29DDD0C<\/i><\/td>\n<td><i>lstrcatW&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>759903FC&nbsp;<\/i><\/td>\n<td><i>CreateDirectoryW<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0A1EFE929<\/i><\/td>\n<td><i>CreateFileW&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0A7FB4165<\/i><\/td>\n<td><i>GetFileSize<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>8B35A289<\/i><\/td>\n<td><i>LocalAlloc&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>95C03D0<\/i><\/td>\n<td><i>ReadFile&nbsp;<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0B09315F4<\/i><\/td>\n<td><i>CloseHandle<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0B1866570<\/i><\/td>\n<td><i>GetModuleHandleA<\/i><\/td>\n<\/tr>\n<tr>\n<td><i>0F54D69C8<\/i><\/td>\n<td><i>CopyFileW&nbsp;<\/i><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span class=\"rte-legal-text\">Table 1. The hashes in the loader\u2019s dynamic API resolving, and their corresponding API names<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>The loader uses an XOR-based algorithm with dynamic key generation for string decryption. For each byte, the algorithm generates a unique key based on its position in the buffer, using the formula <i>(characterIndex % &lt;num1&gt; + &lt;num2&gt;).<\/i> This key is then XORed with the byte to reveal the original character. Each encrypted string has its own decryption function with unique <i>&lt;num1&gt;<\/i> and <i>&lt;num2&gt;<\/i> to make the string decryption automation harder.&nbsp; &nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35\">\n<div readability=\"15\">\n<p>The following is a list of decrypted strings from the first stage loader:&nbsp;&nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>\u201c\/F \/CREATE \/TN &#8220;Licensing2&#8221; \/tr &#8220;C:\\Users\\Public\\Libraries\\Books\\WerFaultSecure.exe&#8221; \/sc minute \/MO 90&#8243;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>\\\\secure.pdf&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>\\\\wer.dll&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>\\\\WerFaultSecure.exe&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>Activeds.dll&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>advapi32&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>AllocADsMem&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>C:\\\\Users\\\\Public\\\\Libraries\\\\Books\\\\secure.pdf&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>C:\\\\Users\\\\Public\\\\Libraries\\\\Books\\\\wer.dll&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>C:\\\\Users\\\\Public\\\\Libraries\\\\Books\\\\WerFaultSecure.exe&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>C:\\Windows\\explorer.exe&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>C:\\Windows\\System32\\schtasks.exe&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>CreateProcessW&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>CryptCATCDFOpen&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>kernel32.dll&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>PathRemoveFileSpecW&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>ReallocADsMem&nbsp;&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>Shlwapi.dll&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\">S<i>ystemFunction032&nbsp;<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>Wintrust.dll&nbsp;<\/i><\/span><\/li>\n<\/ul>\n<p>The loader maintains persistence by creating a directory named <i>C:\\Users\\Public\\Libraries\\Books<\/i> and copies <i>wer.dll<\/i>, <i>secure.pdf<\/i>, and <i>WerFaultSecure.exe<\/i> from the current execution directory to this location. It then executes the <i>schtasks.exe<\/i> command with the arguments <i>&#8220;\/F \/CREATE \/TN \\&#8221;Licensing2\\&#8221; \/tr \\&#8221;C:\\\\Users\\\\Public\\\\Libraries\\\\Books\\\\WerFaultSecure.exe\\&#8221; \/sc minute \/MO 90&#8243;,<\/i> scheduling the <i>WerFaultSecure.exe<\/i> to run at 90-minute intervals.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p>The loader then advances to the second stage wherein the encrypted second-stage loader is in a file called <i>secure.pdf<\/i>. To decrypt it, the malware utilizes an undocumented function, <i>SystemFunction032<\/i> from <i>advapi32.dll<\/i>, which performs RC4 decryption. It then uses the <i>AllocADsMem<\/i> and <i>ReallocADsMem<\/i> functions from <i>Activeds.dll<\/i> to allocate memory and relocate the decrypted content. Finally, it calls VirtualProtect to modify the memory region of the decrypted buffer to Executable-Read-Write.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35\">\n<div readability=\"15\">\n<p>The malware then uses API callback functions to redirect the flow of execution to the second stage. Callback functions are routines that are passed as a parameter to Windows API functions. Later, these routines are called by the API to perform specific functionalities. In the case we investigated, the malware uses the <i>CryptCATCDFOpen<\/i> function, which is used for handling cryptographic catalog files in Windows. It requires two parameters: a file path (<i>pwszFilePath<\/i>) and an optional callback function (<i>PFN_CDF_PARSE_ERROR_CALLBACK<\/i>). The loader passes the second stage shellcode Entry Point (EP) to the second parameter, <i>PFN_CDF_PARSE_ERROR_CALLBACK<\/i>. When the API function is called, the callback function is executed and the malicious code is run.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"51.115671641791\">\n<div readability=\"47.641791044776\">\n<p><span class=\"body-subhead-title\">Second-stage defense evasion<\/span><\/p>\n<p>The attacker used a second-stage loader known as&nbsp;<a href=\"https:\/\/github.com\/TheWover\/donut\">Donut<\/a>, an open-source shellcode that allows the execution of VBScript, JScript, EXE files, DLL files, and .NET assemblies in memory. Donut can be embedded directly into the loader, or it can be staged from an HTTP server or a DNS server. In the case we investigated, the attacker chose to embed it directly into the loader.&nbsp; &nbsp;<\/p>\n<p>Donut can compress input files using aPLib, LZNT1, Xpress, and Xpress Huffman using RtlCompressBuffer. It can also encrypt the payload using the <a href=\"https:\/\/mouha.be\/chaskey\/\">Chaskey<\/a> block cipher. However, in this case, only payload encryption is used, without any compression. &nbsp;&nbsp;<\/p>\n<p>For the final payload execution, Donut is configured to use the Unmanaged CLR Hosting API to load the Common Language Runtime (CLR). Once the CLR is successfully loaded into the host process, a new Application Domain is created to allow for running assemblies in disposable AppDomains. After the AppDomain is ready, Donut loads the .NET assembly and invokes the payload\u2019s entry point.&nbsp;&nbsp;<\/p>\n<p><span class=\"body-subhead-title\">Phemedrone Stealer paylaod analysis<\/span><\/p>\n<ul>\n<li><b>Phemedrone credential access<\/b><\/li>\n<\/ul>\n<p>When executed, the malware initializes its configuration and decrypts certain items such as a Telegram API token, chat ID, and <i>Email_To<\/i> mutex&nbsp;(used for synchronization). This is done using a predefined salt and encryption key and the <i>RijndaelManaged<\/i> symmetric encryption algorithm. The process involves removing the &#8220;<i>CRYPTED:<\/i>&#8221; prefix from the strings, converting the remaining base64-encoded strings into byte arrays and decrypting these arrays to extract the original plain- text values.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>The malware program uses the \u201cMutexCheck.Check()\u201d method to ensure that it doesn&#8217;t operate concurrently with another instance of itself. It does this by creating a mutex and using the value of &#8220;Config.Email_To&#8221; as a synchronization mechanism. If the mutex is already in use, indicating that another instance of the malware is active, the program will immediately terminate itself using \u201cEnvironment.FailFast(&#8220;&#8221;)\u201d. The decrypted mutex value is detected as <i>5dad16bd-6884-4ab8-b182-a504b4c99bcf<\/i>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"41\">\n<div readability=\"27\">\n<p>The malware targets a wide range of applications and services that might exist on a victim&#8217;s computer, aiming in each case to extract specific types of sensitive information:&nbsp;&nbsp;<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Chromium-based browsers<\/b>. <span>The malware harvests data, including passwords, cookies, and autofill information stored in apps such as LastPass, KeePass, NordPass, Google Authenticator, Duo Mobile, and Microsoft Authenticator, among others.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Crypto wallets.<\/b> <span>It extracts files from various cryptocurrency wallet applications such as Armory, Atomic, Bytecoin, Coninomi, Jaxx, Electrum, Exodus, and Guarda.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Discord.<\/b> <span>Phemedrone extracts authentication tokens from the Discord application, enabling unauthorized access to the user&#8217;s account.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>FileGrabber.<\/b> <span>The malware uses this service to gather user files from designated folders such as Documents and Desktop.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>FileZilla.<\/b> <span>Phemedrone captures FTP connection details and credentials from FileZilla.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Gecko.<\/b> <span>The malware targets Gecko-based browsers for user data extraction.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>System Information.<\/b> <span>Phemedrone collects extensive system details, including hardware specs, geolocation, and operating system information, and takes screenshots.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Steam.<\/b> <span>Phemedrone accesses files related to the Steam gaming platform.&nbsp;<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Telegram.<\/b> <span>The malware extracts user data from the installation directory, specifically targeting authentication-related files within the \u201ctdata\u201d folder. This includes seeking out files based on size and naming patterns.&nbsp;<\/span><\/span><\/li>\n<\/ul>\n<p>The malware uses a custom method called <i>RuntimeResolver.GetInheritedClasses&lt;IService&gt;()<\/i> to dynamically find all subclasses of IService. This method uses reflection to scan the assembly. The services are grouped based on their priority levels, allowing them to be processed in a specific order. For each service in the grouped list,&nbsp;Phemedrone creates and starts a new thread. This enables each service to begin its Run method concurrently, which in turn executes the Collect method defined in each service.&nbsp;&nbsp;<\/p>\n<ul>\n<li>Command and control for data exfiltration<\/li>\n<\/ul>\n<p>Once all threads have completed execution, the code iterates through the services again. For each service, it collects the data gathered by the service, and uses the MemoryStream and ZipStorage classes to handle and compress this information. MemoryStream is a flexible in-memory buffer that can store data temporarily, allowing for quick and efficient handling of the information without the need for disk I\/O operations. Following this, ZipStorage is utilized to compress the data into a ZIP file format directly within the MemoryStream.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35.5\">\n<div readability=\"16\">\n<p>Before initiating data exfiltration, the malware validates the Telegram API token using the TokenIsValid method by making an API call to Telegram&#8217;s getMe endpoint. This API call is constructed using the stored Telegram API token. If the response received starts with <i>{&#8220;ok&#8221;:true<\/i>, then it is considered a valid token. However, if any exception occurs during this process, the exception is logged and the method returns false, indicating that the token is not valid.&nbsp;If the token is not valid, it immediately terminates the process by calling <i>Environment.Exit(0)<\/i>.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"44.5\">\n<div readability=\"34\">\n<p>After validating the Telegram API token, the malware proceeds to send the attacker various system information and statistics. This is achieved through the SendMessage method in the <i>global::Telegram.Telegram<\/i> class.&nbsp;&nbsp;<\/p>\n<p>The Collect method gathers extensive system information and statistics, including geolocation data (such as IP, country, city, postal code), hardware information (such as username, machine name, operating system, hardware ID, GPU, CPU, RAM), and data from web browsers (passwords, cookies, credit cards, autofills, extensions, wallets, files), as well as details about installed antivirus products.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.719251336898\">\n<div readability=\"14.879679144385\">\n<p>The following images are an example of a summary report generated by the Phemedrone Stealer, detailing how extensive the data exfiltration via network traffic can be. This report includes key information about the compromised system and user data, encompassing aspects such as geolocation, hardware specifications, web data statistics, and security features of the system<a>.&nbsp;<\/a><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35.5\">\n<div readability=\"16\">\n<p>The next step is to exfiltrate the ZIP-compressed stream containing the full version of the harvested data. This is done through the SendZip method, which uses an HTTP POST request to communicate with the Telegram API. The compressed file is sent as a \u201cdocument\u201d through this request.&nbsp;&nbsp;<\/p>\n<p>The SendZip and MakeFormRequest2 methods are responsible for constructing the multipart\/form-data request. They ensure that the appropriate headers are set and that the file data is streamed correctly. This request is sent to the Telegram sendDocument API endpoint using the bot token and chat ID. The process includes error handling and retries, ensuring that the file upload is successful.&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.5\">\n<div readability=\"8\">\n<p>The snippet in Figure 21 is an example of compressed data exfiltration via Telegram network traffic:&nbsp;&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"45.631535498074\">\n<div readability=\"40.561364887177\">\n<p><span class=\"body-subhead-title\">Conclusion&nbsp;<\/span><\/p>\n<p>Despite having been patched, threat actors continue to find ways to exploit CVE-2023-36025 and evade Windows Defender SmartScreen protections to infect users with a plethora of malware types, including ransomware and stealers like Phemedrone Stealer.&nbsp;&nbsp;<\/p>\n<p>Malware strains such as Phemedrone Stealer highlight the evolving nature of sophisticated malware threats and malicious actors&#8217; ability to quickly enhance their infection chains by adding new exploits for critical vulnerabilities in everyday software. The case discussed here explores the relationship between open-source malware and public proof-of-concept exploits, as significant cross-pollination occurs between the release of a public proof-of-concept and its incorporation into malware infection chains.&nbsp;&nbsp;<\/p>\n<p>Organizations must make sure to update Microsoft Windows installations to prevent being exposed to the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-36025\">Microsoft Windows Defender SmartScreen Bypass (CVE-2023-36025)<\/a>. Public proof-of-concept exploit code exists on the web increasing the risk to organizations who have not yet updated to the latest patched version.<\/p>\n<p>It is critical for organizations to adopt technologies such as&nbsp;<span class=\"rte-red-text\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\">Trend Vision One\u2122\ufe0f<\/a> <\/span>to protect mission-critical data from advanced cyberthreats. Trend Vision One enables security teams to continuously identify known, unknown, managed, and unmanaged cyber assets. It also offers comprehensive prevention, detection, and response capabilities backed by AI, advanced threat research, and intelligence, leading to faster detection, response, and remediation.&nbsp;&nbsp;<\/p>\n<p>Organizations should also consider employing a cutting-edge&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/endpoint-security.html\"><span class=\"rte-red-text\">multilayered defensive strategy<\/span><\/a>&nbsp;via comprehensive security solutions such as&nbsp;<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/services\/managed-xdr.html\"><span class=\"rte-red-text\">Trend Micro\u2122 Managed&nbsp;XDR<\/span><\/a>, which can detect, scan, and block malicious content across the modern threat landscape.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"29.637362637363\">\n<div readability=\"6.6923076923077\">\n<h2><span class=\"body-subhead-title\">Indicators of Compromise (IoCs)<\/span><\/h2>\n<p>You can find the full list of Phemedrone Stealer IoCs <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/24\/a\/cve-2023%E2%80%9336025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/20240111-cve-2023%E2%80%9336025-phemedrone-iocs.txt\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/a\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-steal.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog delves into the Phemedrone Stealer campaign&#8217;s exploitation of CVE-2023-36025, the Windows Defender SmartScreen Bypass vulnerability, for its defense evasion and investigates the malware&#8217;s payload. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":55047,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9555,9509],"class_list":["post-55046","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-12T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/phemedrone-stealer-exploit:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign\",\"datePublished\":\"2024-01-12T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/\"},\"wordCount\":2382,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/\",\"name\":\"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg\",\"datePublished\":\"2024-01-12T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg\",\"width\":710,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-01-12T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/phemedrone-stealer-exploit:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign","datePublished":"2024-01-12T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/"},"wordCount":2382,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/","url":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/","name":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg","datePublished":"2024-01-12T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign.jpg","width":710,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-stealer-campaign\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55046","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55046"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55046\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/55047"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55046"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55046"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}