logo

South Korean hackers exploited WPS Office zero-day to deploy malware

ID: fc72db7b-c805-5333-bcdb-d616ed199486

STIX ID: report--fc72db7b-c805-5333-bcdb-d616ed199486

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ESET researchers uncovered that APT-C-60 exploited a zero-day in WPS Office (CVE-2024-7262) via malicious MHTML documents that invoke the ksoqing:// protocol to load a malicious DLL and deploy the SpyGlace backdoor against East Asian targets; a subsequent incomplete patch introduced CVE-2024-7263. Users are advised to update to WPS Office 12.2.0.17119 and consult published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.