216.73.216.226

XLoader Info-stealer Distributed Using MS Equation Editor Vulnerability (CVE-2017-11882)

· Published 01/05/2025 14:50 · Modified 01/05/2025 20:26

Export JSON

Essential information

Published
01/05/2025 14:50
Modified
01/05/2025 20:26
Tags
2025-05-01 CVE-2017-11882 horusprotector info-stealer ms equation editor phishing regasm.exe rtf vbe xloader
Related entities
8 techniques (mitre), 1 malware

Description

An analysis reveals the distribution of through emails exploiting the vulnerability (). The attack begins with a DOCX file containing an document that creates a file in a temporary folder. This file, built using , contains the final malware and creates registry keys for execution. The malware process injects into and executes the . The distribution method has evolved from single files to Office documents with embedded vulnerabilities, indicating persistent risks in unpatched environments. Users are advised to update their Office products and exercise caution when opening email attachments from unknown sources.