logo

7-Year-Old 0-Day in Microsoft Office Exploited to Drop Cobalt Strike

ID: 70819ef9-7832-5ca2-933b-29172e4823ad

STIX ID: report--70819ef9-7832-5ca2-933b-29172e4823ad

Feed Name: HackRead

Threat Score
72/100

Date Published: 2024-04-26

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Deep Instinct identified a targeted campaign against Ukrainian systems that leveraged an old Microsoft Office vulnerability (CVE-2017-8570) in a malicious PPSX lure to deploy a cracked custom Cobalt Strike Beacon loader; operators used obfuscated script URLs and deceptive domains (weavesilk.space, petapixel.fun), staged infrastructure across multiple countries, and evaded easy attribution, highlighting the continued risk from legacy vulnerabilities and sophisticated C2 tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.