Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)
ID: f6b906ac-f88b-56af-b62c-364251dedf21
STIX ID: report--f6b906ac-f88b-56af-b62c-364251dedf21
Feed Name: ASEC
Threat Score
**Executive summary:** AhnLab ASEC details a Kimsuky campaign exploiting CVE-2017-11882 in MS Office EQNEDT32.EXE to launch a malicious mshta-hosted script (error.php) that uses PowerShell to download a downloader and a keylogger, establish persistence (desktop.ini.bak in public folders and Run key registration), collect system/IP and keystroke/clipboard data, and communicate with C2 servers; the report includes file detections, MD5 hashes, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
