logo

Microsoft Office 0-Day leveraged in spam campaigns

ID: 8797b001-2d93-5a70-8121-93fe7c5150b4

STIX ID: report--8797b001-2d93-5a70-8121-93fe7c5150b4

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A spam campaign abused Microsoft Office vulnerability CVE-2017-0199 by delivering malicious RTF documents that load external content and run embedded VBScript/PowerShell to download and execute further payloads (notably Dridex and LATENTBOT); Zscaler ThreatLabZ observed and blocked exploitation attempts, provides IoCs (URLs, filenames), and recommends ensuring Office is fully patched and verifying email attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.