New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

First seen 29 May 2026, 10:39 UTC Feeds.Feedburnerwww.fortinet.comwww.mcafee.com 81% similarity 70.5

Article Content

Browse articles
ThreatCluster

A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits CVE-2017-11882, allowing full remote control of the victim's computer. The phishing email masquerades as a legitimate message from a shipping company in Vietnam, enticing users to open the attached document. The attack leverages a fileless execution method, employing PowerShell and VBScript to load the Remcos agent. This campaign is notable for its sophisticated use of URL shortening and remote template features in Microsoft Word. FortiGuard Labs reported the campaign, highlighting its high severity and potential impact on users. Current defenses, including FortiMail, can block the phishing emails before delivery.

Key Points: • The campaign exploits CVE-2017-11882, a known vulnerability in Microsoft Equation Editor. • Phishing emails are disguised as shipping documents to lure victims into opening malicious attachments. • The attack employs a fileless execution method using PowerShell and VBScript for stealth.

ThreatCluster AI

Timeline

2021-11-03
CVE-2017-11882 added to CISA KEV
CISA recognized CVE-2017-11882 for active exploitation, prompting heightened awareness among cybersecurity professionals.
Article 1
2026-05-29
New Remcos RAT campaign discovered
FortiGuard Labs identified a phishing campaign delivering Remcos RAT via a fake shipping document, impacting Windows users.
Article 1

Community

Browse all →