South Korean hackers exploited WPS Office zero-day to deploy malware
ID: fc72db7b-c805-5333-bcdb-d616ed199486
STIX ID: report--fc72db7b-c805-5333-bcdb-d616ed199486
Feed Name: Bleeping Computer
Threat Score
ESET researchers uncovered that APT-C-60 exploited a zero-day in WPS Office (CVE-2024-7262) via malicious MHTML documents that invoke the ksoqing:// protocol to load a malicious DLL and deploy the SpyGlace backdoor against East Asian targets; a subsequent incomplete patch introduced CVE-2024-7263. Users are advised to update to WPS Office 12.2.0.17119 and consult published IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
