Feeds.Feedburner New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
Article Content
- •The campaign exploits CVE-2017-11882, a known vulnerability in Microsoft Equation Editor.
- •Phishing emails are disguised as shipping documents to lure victims into opening malicious attachments.
- •The attack employs a fileless execution method using PowerShell and VBScript for stealth.
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits CVE-2017-11882, allowing full remote control of the victim's computer. The phishing email masquerades as a legitimate message from a shipping company in Vietnam, enticing users to open the attached document. The attack leverages a fileless execution method, employing PowerShell and VBScript to load the Remcos agent. This campaign is notable for its sophisticated use of URL shortening and remote template features in Microsoft Word. FortiGuard Labs reported the campaign, highlighting its high severity and potential impact on users. Current defenses, including FortiMail, can block the phishing emails before delivery.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Agent Tesla and CVE-2017-11882 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New Agent Tesla Malware Variant Uses Emojis for Evasion in BEC Campaign A new variant of the Agent Tesla malware, identified as version 4, employs Unicode emoji characters to obfuscate its JScript dropper in a business email compromise (BEC) campaign targeting finance departments. The malware impersonates the Metropolitan Bank and Trust Company in a forwarded email, urging recipients to…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…