Feeds.Feedburner
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
Article Content
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits CVE-2017-11882, allowing full remote control of the victim's computer. The phishing email masquerades as a legitimate message from a shipping company in Vietnam, enticing users to open the attached document. The attack leverages a fileless execution method, employing PowerShell and VBScript to load the Remcos agent. This campaign is notable for its sophisticated use of URL shortening and remote template features in Microsoft Word. FortiGuard Labs reported the campaign, highlighting its high severity and potential impact on users. Current defenses, including FortiMail, can block the phishing emails before delivery.
Key Points: • The campaign exploits CVE-2017-11882, a known vulnerability in Microsoft Equation Editor. • Phishing emails are disguised as shipping documents to lure victims into opening malicious attachments. • The attack employs a fileless execution method using PowerShell and VBScript for stealth.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.