# CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities (UAC-0194 / SparkRAT)

> CVE-2024-43451 is a Windows NTLM hash disclosure spoofing zero-day (CVSS 6.5) that leaks a victim's NTLMv2 hash on minimal interaction with a malicious internet-shortcut (.url) file — single-click, right-click inspection, deletion, or drag. Russia-linked UAC-0194 weaponized it against Ukrainian entities via phishing sent from a compromised Ukrainian government server (doc.osvita-kp.gov.ua), ultimately deploying the open-source SparkRAT. ClearSky discovered the activity in June 2024; Microsoft patched it on 2024-11-12 and CISA added it to the KEV catalog.

- **Published:** 2026-06-10T00:00:00Z
- **Last reviewed:** 2026-06-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0761
- **ID:** TL-2026-0761
- **Severity:** HIGH (CVSS 6.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Actor:** UAC-0194 (Russia)
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-43451

## Description

CVE-2024-43451 is an NTLM hash disclosure spoofing vulnerability in Windows NT LAN Manager (NTLM) authentication. The flaw allows an attacker to coerce a victim's machine into disclosing the user's NTLMv2 hash with only minimal interaction with a specially crafted Windows internet shortcut (.url) file. Unlike conventional shortcut abuse that requires opening or executing a file, CVE-2024-43451 is triggered by ordinary, low-friction user actions: single-clicking (selecting) the file, right-clicking it to inspect properties, deleting it, or dragging/moving it. Any of these actions causes the .url file to initiate an outbound SMB connection to an attacker-controlled server, during which the victim's NTLMv2 challenge-response hash is transmitted and captured. Microsoft classifies the trigger as 'minimal interaction with a malicious file by a user such as selecting (single-click), inspecting (right-click), or performing an action other than opening or executing.'

The vulnerability was discovered as a zero-day by ClearSky Cyber Security in June 2024, with the earliest weaponized .url samples uploaded to VirusTotal as far back as April 2024. The exploitation campaign was attributed by Ukraine's CERT-UA to the threat cluster UAC-0194, assessed to be Russia-linked. The attack chain begins with spear-phishing emails sent from a compromised Ukrainian government server (doc.osvita-kp.gov.ua, an education-sector certificate distribution host). The lures impersonate a request to renew an academic certificate and contain a link that downloads a ZIP archive bundling a decoy PDF and a malicious .url internet-shortcut file. When the recipient interacts with the .url file, CVE-2024-43451 is triggered: the shortcut reaches out over SMB to the attacker infrastructure, leaking the NTLMv2 hash (enabling later pass-the-hash and offline cracking) and pulling down a follow-on executable masquerading as a certificate installer.

Post-exploitation, the operators used AutoIT to deliver and execute SparkRAT, an open-source Go-based remote access trojan. SparkRAT establishes persistence by dropping a script under 'Wave360 Sync Technologies Co\SyncWave360.js' in the user's Startup folder and beacons to its command-and-control server over a non-standard port (TCP 8000). The campaign also dropped a .cmd component that enumerates running processes (tasklist) and probes for installed security software (findstr), and in related activity RedLine Stealer was observed as an alternative payload. CERT-UA reported more than 30 unique IP addresses tied to UAC-0194 infrastructure across the campaign, with 92.42.96.30 identified as a SparkRAT C2 endpoint. Microsoft shipped a fix in the November 2024 Patch Tuesday (2024-11-12); CISA added CVE-2024-43451 to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, underscoring confirmed active exploitation.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1588.001 Malware
- T1588.005 Exploits
- T1566.002 Spearphishing Link
- T1566.001 Spearphishing Attachment
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059.003 Windows Command Shell
- T1203 Exploitation for Client Execution
- T1547.001 Registry Run Keys / Startup Folder
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1059 Command and Scripting Interpreter
- T1187 Forced Authentication
- T1003 OS Credential Dumping
- T1057 Process Discovery
- T1518.001 Security Software Discovery
- T1082 System Information Discovery
- T1021.002 SMB/Windows Admin Shares
- T1550.002 Pass the Hash
- T1219 Remote Access Tools
- T1571 Non-Standard Port
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol

## Sources

- [CVE-2024-43451: A New Zero-Day Vulnerability Exploited in the Wild](https://www.clearskysec.com/0d-vulnerability-exploited-in-the_wild/)
- [CVE-2024-43451 NTLM Hash Disclosure Spoofing Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451)
- [NVD - CVE-2024-43451](https://nvd.nist.gov/vuln/detail/CVE-2024-43451)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2024-43451](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails](https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html)
- [UAC-0194 Targets Ukraine with CVE-2024-43451 Exploits](https://www.anvilogic.com/threat-reports/uac-0194-cve-2024-43451)
- [How a Windows zero-day was exploited in the wild for months (CVE-2024-43451)](https://www.helpnetsecurity.com/2024/11/14/cve-2024-43451-exploited/)
- [UAC-0194 Threat Actor Profile](https://malpedia.caad.fkie.fraunhofer.de/actor/uac-0194)
- [CVE-2024-43451: Windows NTLM Hash Disclosure Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2024-43451/)
- [CVE-2024-43451 Proof-of-Concept (NTLM forced authentication via malicious shortcut)](https://github.com/RonF98/CVE-2024-43451-POC)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0761
