logo

MerkSpy: Exploiting CVE-2021-40444 to Infiltrate Systems

ID: 3c81d412-d2d2-522a-b9a5-4f832748464a

STIX ID: report--3c81d412-d2d2-522a-b9a5-4f832748464a

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2024-06-27

Date Updated: 2026-04-27

...
...

FortiGuard Labs reports a high-severity campaign exploiting CVE-2021-40444 via a malicious Word document that downloads an HTML payload (olerender.html) containing XOR-encoded shellcode. The shellcode decodes and runs a downloader that retrieves a VMProtect-protected payload named "GoogleUpdate," which injects the MerkSpy spyware into system processes, establishes persistence via a Run registry entry, and exfiltrates keystrokes, screenshots, Chrome credentials and MetaMask data to 45.89.53.46; the report includes IOCs and Fortinet detection names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.