logo

Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)

ID: f6b906ac-f88b-56af-b62c-364251dedf21

STIX ID: report--f6b906ac-f88b-56af-b62c-364251dedf21

Feed Name: ASEC

Threat Score
72/100

Date Published: 2024-06-13

Date Updated: 2026-04-26

Author: EASTSTON3

...
...

**Executive summary:** AhnLab ASEC details a Kimsuky campaign exploiting CVE-2017-11882 in MS Office EQNEDT32.EXE to launch a malicious mshta-hosted script (error.php) that uses PowerShell to download a downloader and a keylogger, establish persistence (desktop.ini.bak in public folders and Run key registration), collect system/IP and keystroke/clipboard data, and communicate with C2 servers; the report includes file detections, MD5 hashes, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.