Hacking

Windows NTLM Zero-Day Exploited by Russian Hackers Targeting Ukraine

Published  ·  2 min read

A recent NTLM vulnerability in Windows, tracked as CVE-2024-43451 (CVSS 6.5), has been exploited in zero-day attacks against Ukraine. The vulnerability, patched by Microsoft in November 2024, allows attackers to steal a user's NTLMv2 hash through minimal user interaction with a malicious file, such as right-clicking or selecting a URL file.

Israeli cybersecurity company ClearSky revealed that this flaw has been used as part of an attack chain delivering the Spark RAT malware. These attacks target Ukrainian organizations with phishing emails from a compromised government server, prompting users to download malicious files from an official-looking site.

Key Details of the Vulnerability

  1. CVE-2024-43451: An NTLM spoofing vulnerability allowing hash disclosure.
  2. Triggered through minor interactions with a .URL file containing malicious links.
  3. Attack chain: Involves compromised Ukrainian government servers and phishing emails that lead to the download of a ZIP file containing the malicious URL file.

Attack Mechanism

The phishing emails appear to originate from Ukraine’s doc.osvita-kp.gov[.]ua server and instruct recipients to renew academic certificates. Interaction with the malicious URL file activates the attack chain, connecting to a remote server to download Spark RAT, enabling hackers to execute additional payloads and potentially steal NTLM hashes.

Exploitation and Implications

The flaw exploits NTLM hash disclosure via the SMB protocol, potentially allowing attackers to conduct Pass-the-Hash (PtH) attacks for lateral movement within the network. Ukrainian authorities attribute the attack to a Russian-affiliated group, UAC-0194. In a similar campaign, CERT-UA also reported financially motivated phishing attacks using LiteManager to target accountants in Ukraine, with risks of rapid bank fraud.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067