Skip to content
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

First seen 29 May 2026, 10:39 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 30, 2026 at 10:21 UTC

A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits CVE-2017-11882, allowing full remote control of the victim's computer. The phishing email masquerades as a legitimate message from a shipping company in Vietnam, enticing users to open the attached document. The attack leverages a fileless execution method, employing PowerShell and VBScript to load the Remcos agent. This campaign is notable for its sophisticated use of URL shortening and remote template features in Microsoft Word. FortiGuard Labs reported the campaign, highlighting its high severity and potential impact on users. Current defenses, including FortiMail, can block the phishing emails before delivery.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 103d ago How this analysis works

Timeline

2021-11-03
CVE-2017-11882 added to CISA KEV
CISA recognized CVE-2017-11882 for active exploitation, prompting heightened awareness among cybersecurity professionals.
Article 1
2026-05-29
New Remcos RAT campaign discovered
FortiGuard Labs identified a phishing campaign delivering Remcos RAT via a fake shipping document, impacting Windows users.
Article 1

More articles in this cluster (3)

Following this threat?

Track Agent Tesla and CVE-2017-11882 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed