logo

Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool

ID: a12d0e9a-4da8-597b-a872-937e0223b63f

STIX ID: report--a12d0e9a-4da8-597b-a872-937e0223b63f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-03

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Unknown threat actors exploited the patched MSHTML vulnerability CVE-2021-40444 via malicious Microsoft Word documents to deploy MerkSpy — a memory-resident spyware/infostealer that uses an HTML-based shellcode downloader (olerender.html) and an injector disguised as "GoogleUpdate" to evade detection, persist via Windows Registry changes, and exfiltrate screenshots, keystrokes, Chrome-stored credentials and MetaMask data to 45.89.53.46/google/update.php; the campaign has targeted users in Canada, India, Poland, and the U.S., and related smishing credential-phishing activity was also observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.