Newfuture Trojan V.1.0 BETA 1 malware suffers from an insecure permissions vulnerability.

MD5 | e267f7d69761b3693f04b9c14690bfa6

Discovery / credits: Malvuln - (c) 2021
Contact: [email protected]

Threat: Newfuture Trojan V.1.0 BETA 1
Vulnerability: Insecure Permissions
Description: Newfuture by Wider is a remote access client and has a (Fast_sms) server component, it is written in spanish. On installation it grants (C) change privileges to Authenticated users group allowing EoP.

Type: PE32
MD5: 4f9376824718ff23a6238c877f73ff73
Vuln ID: MVID-2021-0032
Disclosure: 01/18/2021

C:\>cacls "C:\Archivos de Programa\Newfuture Trojan BETA 1"
C:\Archivos de Programa\Newfuture Trojan BETA 1 BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C

