Socprime
Malware Campaign Utilizes Reused JPEG for Payload Delivery
Article Content
A malware campaign has been identified that exploits Microsoft Equation Editor (CVE-2017-11882) to deliver a malicious payload embedded in a JPEG image. The campaign uses a specific attachment named 'TELERADIO_IB_OBYEKTLRIN_BURAXILIS_FORMASI.xIs' to initiate the infection chain, which includes downloading an HTA file that executes PowerShell to retrieve a .NET binary. The reuse of the JPEG image across multiple samples indicates a reliance on consistent tactics by the attackers.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.