logo

MSDT Vulnerability CVE-2022-30190 Exploited For PowerShell

ID: b94c8ec9-5dca-5aea-8bef-f552a8470e78

STIX ID: report--b94c8ec9-5dca-5aea-8bef-f552a8470e78

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-17

...
...

Cyble Research Labs documents active in-the-wild exploitation of CVE-2022-30190 (MSDT/Follina) using malicious RTF files that embed an OLE object to load an HTML exploit which downloads a PowerShell-based information stealer; the stealer harvests browser and application credentials, specific registry keys, runs system discovery commands, compresses data and exfiltrates logs to a public C2 (45.77.156.179). The report provides IoCs (hashes, URLs, IP), MITRE ATT&CK mappings, and remediation recommendations (Microsoft mitigations, MFA, patching, antivirus, DLP, network monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.