Socprime
Malware Campaign Utilizes Reused JPEG for Payload Delivery
First seen 19 Feb 2026, 02:19 UTC
•
•30.6
Export
Article Content
Browse articles
A malware campaign has been identified that exploits Microsoft Equation Editor (CVE-2017-11882) to deliver a malicious payload embedded in a JPEG image. The campaign uses a specific attachment named 'TELERADIO_IB_OBYEKTLRIN_BURAXILIS_FORMASI.xIs' to initiate the infection chain, which includes downloading an HTA file that executes PowerShell to retrieve a .NET binary. The reuse of the JPEG image across multiple samples indicates a reliance on consistent tactics by the attackers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2017-11-15
CVE-2017-11882 published
2017-11-21
First public PoC for CVE-2017-11882
2021-11-03
CVE-2017-11882 added to CISA KEV (active exploitation)
2026-02-18
Discovery of new malware campaign using JPEG technique
2026-02-19
Socprime article published on malware campaign