Keylogger Installed Using MS Office Equation Editor Vulnerability (Kimsuky)
2024-06-13 • Ahnlab •
ASEC reported that Kimsuky exploited CVE-2017-11882 in the MS Office Equation Editor to launch mshta and run a malicious script that distributed a keylogger. The script connected to an error.php page that displayed a fake "Not Found" message while downloading additional malware from the C2 with PowerShell. Follow-on code collected system and IP information, could fetch the keylogger with a separate C2 query, and wrote keylogging and clipboard data to desktop.ini.bak under Users\Public\Music. The keylogger used a Global\AlreadyRunning19122345 mutex, exfiltrated collected data to the C2 at actor-controlled intervals, and the report lists related VBS, PowerShell downloader, keylogger detections, and sample hashes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 279c86f3796d14d2a4d89049c2b3fa2d | 2024-05-29 | 2024-06-13 |
| HASH | 5bfeef520eb1e62ea2ef313bb979aeae | 2024-05-29 | 2024-06-13 |
| HASH | d404ab9c8722fc97cceb95f258a2e70d | 2024-05-29 | 2024-06-13 |