Threat reportVulnerabilityTL-2026-0761

CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities (UAC-0194 / SparkRAT)

highPATCHED

CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day (TL-2026-0761), also tracked as Windows NTLM Hash Disclosure Spoofing Zero-Day, is a high-severity software vulnerability scored CVSS 6.5, first published 2026-06-10. It is attributed to UAC-0194 (Russia) with medium confidence, affects Microsoft Windows 10, references 1 CVE (CVE-2024-43451), maps to 24 MITRE ATT&CK techniques (T1003, T1021.002, T1027), and is covered by 9 detection rules and 19 indicators of compromise.

CVSS
6.5/10High
CVEs
1Referenced vulnerabilities
Techniques
24MITRE ATT&CK
Actors
1UAC-0194
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-0761

Threat ID
TL-2026-0761
Also known as
Windows NTLM Hash Disclosure Spoofing Zero-Day, UAC-0194 Academic Certificate Phishing Campaign
Severity
HIGH
CVSS
6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution
UAC-0194
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, education, academic
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
19

Malware and tooling in CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

Malware and tooling: RedLine Stealer - S1240, SparkRAT, AutoIT, SparkRAT (TCP 8000)

How CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day works

CVE-2024-43451 is a Windows NTLM hash disclosure spoofing zero-day (CVSS 6.5) that leaks a victim's NTLMv2 hash on minimal interaction with a malicious internet-shortcut (.url) file — single-click, right-click inspection, deletion, or drag. Russia-linked UAC-0194 weaponized it against Ukrainian entities via phishing sent from a compromised Ukrainian government server (doc.osvita-kp.gov.ua), ultimately deploying the open-source SparkRAT. ClearSky discovered the activity in June 2024; Microsoft patched it on 2024-11-12 and CISA added it to the KEV catalog.

CVE-2024-43451 is an NTLM hash disclosure spoofing vulnerability in Windows NT LAN Manager (NTLM) authentication. The flaw allows an attacker to coerce a victim's machine into disclosing the user's NTLMv2 hash with only minimal interaction with a specially crafted Windows internet shortcut (.url) file. Unlike conventional shortcut abuse that requires opening or executing a file, CVE-2024-43451 is triggered by ordinary, low-friction user actions: single-clicking (selecting) the file, right-clicking it to inspect properties, deleting it, or dragging/moving it. Any of these actions causes the .url file to initiate an outbound SMB connection to an attacker-controlled server, during which the victim's NTLMv2 challenge-response hash is transmitted and captured. Microsoft classifies the trigger as 'minimal interaction with a malicious file by a user such as selecting (single-click), inspecting (right-click), or performing an action other than opening or executing.'

The vulnerability was discovered as a zero-day by ClearSky Cyber Security in June 2024, with the earliest weaponized .url samples uploaded to VirusTotal as far back as April 2024. The exploitation campaign was attributed by Ukraine's CERT-UA to the threat cluster UAC-0194, assessed to be Russia-linked. The attack chain begins with spear-phishing emails sent from a compromised Ukrainian government server (doc.osvita-kp.gov.ua, an education-sector certificate distribution host). The lures impersonate a request to renew an academic certificate and contain a link that downloads a ZIP archive bundling a decoy PDF and a malicious .url internet-shortcut file. When the recipient interacts with the .url file, CVE-2024-43451 is triggered: the shortcut reaches out over SMB to the attacker infrastructure, leaking the NTLMv2 hash (enabling later pass-the-hash and offline cracking) and pulling down a follow-on executable masquerading as a certificate installer.

Post-exploitation, the operators used AutoIT to deliver and execute SparkRAT, an open-source Go-based remote access trojan. SparkRAT establishes persistence by dropping a script under 'Wave360 Sync Technologies Co\SyncWave360.js' in the user's Startup folder and beacons to its command-and-control server over a non-standard port (TCP 8000). The campaign also dropped a .cmd component that enumerates running processes (tasklist) and probes for installed security software (findstr), and in related activity RedLine Stealer was observed as an alternative payload. CERT-UA reported more than 30 unique IP addresses tied to UAC-0194 infrastructure across the campaign, with 92.42.96.30 identified as a SparkRAT C2 endpoint. Microsoft shipped a fix in the November 2024 Patch Tuesday (2024-11-12); CISA added CVE-2024-43451 to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, underscoring confirmed active exploitation.

MITRE ATT&CK techniques used in TL-2026-0761

Credential Access

T1003 OS Credential Dumping; T1187 Forced Authentication

Lateral Movement

T1021.002 SMB/Windows Admin Shares; T1550.002 Pass the Hash

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

execution

T1059 Command and Scripting Interpreter

Execution

T1059.003 Windows Command Shell; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1571 Non-Standard Port

Persistence

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1584 Compromise Infrastructure; T1588.001 Malware; T1588.005 Exploits

Affected products and versions in CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

  • Microsoft — Windows 10
    Vulnerable versions: 1507; 1607; 1809; 21H2; 22H2
    Fixed in: Patched via 2024-11-12 cumulative update
  • Microsoft — Windows 11
    Vulnerable versions: 22H2; 23H2; 24H2
    Fixed in: Patched via 2024-11-12 cumulative update
  • Microsoft — Windows (legacy)
    Vulnerable versions: Windows 7; Windows 8; Windows 8.1
    Fixed in: ESU update released 2024-11-12
  • Microsoft — Windows Server
    Vulnerable versions: 2008; 2008 R2; 2012; 2012 R2; 2016; 2019; 2022; 2025
    Fixed in: Patched via 2024-11-12 cumulative update

Remediation for CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

Patches

  • Microsoft Security Update KB chain released 2024-11-12 (November 2024 Patch Tuesday) addressing CVE-2024-43451 for all supported Windows versions

Immediate actions

  • Apply the Microsoft November 2024 (2024-11-12) security update for CVE-2024-43451 across all Windows 7/8/8.1/10/11 and Windows Server builds
  • Block outbound SMB (TCP 445) and NetBIOS (TCP 139) at the network perimeter to prevent NTLMv2 hash leakage to external hosts
  • Block the known C2 indicator 92.42.96.30 and SparkRAT C2 traffic on TCP 8000 at the firewall/proxy
  • Quarantine and inspect any .url internet-shortcut files delivered via email or ZIP archives, especially those referencing certificate renewal lures

Workarounds

  • Apply Microsoft's NTLM relay/forced-authentication hardening guidance and restrict outbound NTLM traffic to remote servers via Group Policy ('Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers')
  • Use mail-gateway rules to block or detonate ZIP archives containing .url shortcut files

Longer-term hardening

  • Enforce SMB signing and disable outbound SMB to the internet via firewall and host policy
  • Enable Network Protection / SmartScreen and strip or sandbox .url attachments at the mail gateway
  • Migrate from NTLM to Kerberos where possible and enable Extended Protection for Authentication (EPA)
  • Deploy EDR with behavioral detection for AutoIT-delivered payloads, Startup-folder script persistence, and unusual outbound NTLM authentication

CVEs associated with CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

CVE-2024-43451

Weaknesses (CWE) in CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

CWE-73

Timeline of CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

  • Earliest weaponized malicious .url internet-shortcut samples exploiting CVE-2024-43451 uploaded to VirusTotal, indicating in-the-wild use months before disclosure.
  • ClearSky Cyber Security discovers the zero-day exploitation activity targeting Ukrainian entities via malicious .url files.
  • CISA adds CVE-2024-43451 to the Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a federal remediation deadline.
  • CVE-2024-43451 published in the NVD with CVSS 3.1 base score 6.5 (vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N), CWE-73.
  • Microsoft releases the fix for CVE-2024-43451 as part of the November 2024 Patch Tuesday.
  • ClearSky publishes its public report attributing the campaign to UAC-0194 and detailing SparkRAT delivery via phishing from compromised server doc.osvita-kp.gov.ua.
  • The Hacker News and Help Net Security report the C2 endpoint 92.42.96.30 and the academic-certificate-renewal phishing lure.
  • NVD record for CVE-2024-43451 last modified, reflecting continued reference and affected-product updates.

Sources cited for CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day

Detection coverage for TL-2026-0761

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0761 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats