logo

'Ancient' MSFT Word Bug Anchors Taiwanese Drone-Maker Attacks

ID: f6a98556-e2aa-5ce8-96cb-4967534d21ac

STIX ID: report--f6a98556-e2aa-5ce8-96cb-4967534d21ac

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-09-11

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Acronis researchers disclosed 'WordDrone', a targeted campaign that leverages an outdated Microsoft Word (v14.0.4762.1000) side-loading flaw to load a malicious wwlib.dll loader and an encrypted payload delivering the ClientEndPoint backdoor; the activity, observed across multiple environments between April and July and potentially tied to Digiwin ERP components, enables session monitoring, C2 communications, data exfiltration and local-network proxying, and was shared with Taiwanese authorities along with IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.