logo

Analysis Of SandWorm (CVE-2014-4114) 0-Day

ID: 5445aa2f-9b27-5463-9cb5-9ea061f3ad57

STIX ID: report--5445aa2f-9b27-5463-9cb5-9ea061f3ad57

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** This report analyzes an in-the-wild zero-day exploit (CVE-2014-4114) delivered via a malicious PowerPoint Slide Show (spiski_deputatov_done.ppsx) that uses embedded OLE objects to retrieve a BlackEnergy executable disguised as a GIF and an INF file (slides.inf) that renames and executes the payload; the campaign is linked to a possible Russian espionage effort targeting NATO, EU, telecommunications, and energy sectors and Zscaler's engines detected and blocked the sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.