Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)

2024-06-13 Ahnlab

https://asec.ahnlab.com/en/66720/

Thumbnail for Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)

ASEC reported that Kimsuky exploited CVE-2017-11882 in the MS Office Equation Editor to launch mshta and run a malicious script that distributed a keylogger. The script connected to an error.php page that displayed a fake "Not Found" message while downloading additional malware from the C2 with PowerShell. Follow-on code collected system and IP information, could fetch the keylogger with a separate C2 query, and wrote keylogging and clipboard data to desktop.ini.bak under Users\Public\Music. The keylogger used a Global\AlreadyRunning19122345 mutex, exfiltrated collected data to the C2 at actor-controlled intervals, and the report lists related VBS, PowerShell downloader, keylogger detections, and sample hashes.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 279c86f3796d14d2a4d89049c2b3fa2d 2024-05-29 2024-06-13
HASH 5bfeef520eb1e62ea2ef313bb979aeae 2024-05-29 2024-06-13
HASH d404ab9c8722fc97cceb95f258a2e70d 2024-05-29 2024-06-13

Related Actors

Related Reports

« Back