logo

South Korean APT Exploits 1-Click WPS Office Bug, Nabs Chinese Intel

ID: 871b27db-5192-5e6e-be5a-f98b35048d9e

STIX ID: report--871b27db-5192-5e6e-be5a-f98b35048d9e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-08-29

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Earlier this year South Korea–aligned APT-C-60 exploited critical WPS Office arbitrary-code-execution flaws (CVE-2024-7262 and CVE-2024-7263) to deliver the SpyGlace backdoor to Chinese targets via a crafted MHTML/XLS one-click attack that abused the ksoqing:// protocol and an insecure promecefpluginhost.exe plugin-loading mechanism; both bugs were rated CVSS 9.3 and were patched after active exploitation, and users are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.