logo

Malspam Campaigns Use Malicious RTF Documents

ID: 2089afb7-7e72-5f5c-8f35-8430a2ec5c4b

STIX ID: report--2089afb7-7e72-5f5c-8f35-8430a2ec5c4b

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents a phishing-driven campaign that uses malicious RTF files exploiting CVE-2017-8570 and CVE-2018-0802 to drop and execute LokiBot payloads; the report details exploit mechanics (Packager.dll, composite monikers, equation editor overflow), LokiBot persistence and information-stealing capabilities, artifacts and IOCs (MD5 hashes, domains, IPs, paths), and recommended detections/protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.