Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool
ID: a12d0e9a-4da8-597b-a872-937e0223b63f
STIX ID: report--a12d0e9a-4da8-597b-a872-937e0223b63f
Feed Name: The Hacker News
Unknown threat actors exploited the patched MSHTML vulnerability CVE-2021-40444 via malicious Microsoft Word documents to deploy MerkSpy — a memory-resident spyware/infostealer that uses an HTML-based shellcode downloader (olerender.html) and an injector disguised as "GoogleUpdate" to evade detection, persist via Windows Registry changes, and exfiltrate screenshots, keystrokes, Chrome-stored credentials and MetaMask data to 45.89.53.46/google/update.php; the campaign has targeted users in Canada, India, Poland, and the U.S., and related smishing credential-phishing activity was also observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
