South Korean APT Exploits 1-Click WPS Office Bug, Nabs Chinese Intel
ID: 871b27db-5192-5e6e-be5a-f98b35048d9e
STIX ID: report--871b27db-5192-5e6e-be5a-f98b35048d9e
Feed Name: Dark Reading
Threat Score
Earlier this year South Korea–aligned APT-C-60 exploited critical WPS Office arbitrary-code-execution flaws (CVE-2024-7262 and CVE-2024-7263) to deliver the SpyGlace backdoor to Chinese targets via a crafted MHTML/XLS one-click attack that abused the ksoqing:// protocol and an insecure promecefpluginhost.exe plugin-loading mechanism; both bugs were rated CVSS 9.3 and were patched after active exploitation, and users are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
