#threatreport #MediumCompleteness
Beware of phishing emails disguised as project material purchase request forms | 29-09-2026
Source: https://asec.ahnlab.com/ko/95596/
Key details below ↓
💀Threats:
Steganography_technique, Remcos_rat,
🔓CVEs: CVE-2017-0199 \[[Vulners](https://vulners.com/cve/CVE-2017-0199)]
- CVSS V3.1: *7.8*,
- Vulners: Exploitation: True
Soft:
- microsoft office (2007, 2010, 2013, 2016)
- microsoft windows_7 (-)
- microsoft windows_server_2008 (-, r2)
- microsoft windows_server_2012 (-)
...
🤖LLM extracted TTPs:`
T1027, T1027.003, T1036, T1041, T1047, T1056.001, T1059.001, T1082, T1105, T1113, ...
🧨IOCs:
- Url: 3
- Domain: 1
- IP: 1
- Hash: 3
💽Software: Microsoft Office
🔢Algorithms: md5, base64
📜Programming Languages: powershell
#threatreport:
A phishing campaign distributes emails impersonating employees of a domestic company and presenting malicious XLS attachments as project materials purchase request forms. When opened, the spreadsheet displays legitimate-looking purchase request content as a decoy. The document exploits CVE-2017-0199, a Microsoft Office remote code execution vulnerability involving OLE2Link functionality. This allows the document to access an external URL and download additional payloads, including an HTA file, without relying solely on user interaction.
The downloaded HTA script uses Windows Management Instrumentation (WMI), specifically the `Win32_Process.Create()` method, to execute an obfuscated PowerShell script in the background. After deobfuscation, the PowerShell script retrieves a PNG file from another command-and-control (C2) server. The image contains embedded data using steganography. The script searches for the markers `IN-` and `-inl`, extracts Base64-encoded data located between them, and processes it as a .NET loader.
The extracted loader is decrypted, loaded, and executed directly in memory. It receives the address of a C2 server as an argument and uses that server to download and execute Remcos RAT. The malware can receive and execute commands remotely, collect system and user information, log keystrokes, capture screenshots, and manipulate files. It sends collected information and command execution results to external infrastructure through C2 communications. The attack chain therefore combines social engineering, exploitation of CVE-2017-0199, WMI-based execution, obfuscated PowerShell, steganographic payload concealment, in-memory .NET loading, and deployment of a remote access trojan.