ThreadKit is a Microsoft Office document exploit builder kit first observed in the wild by at least June 2017 and later advertised on underground forums. It is a generation framework used to create malicious Office documents that weaponize multiple Office vulnerabilities over time, including CVE-2017-0199, CVE-2017-8759, CVE-2017-11882, CVE-2017-8570, and CVE-2018-0802. Proofpoint reported that ThreadKit-generated documents commonly included a built-in infection-statistics check-in mechanism, often implemented via Microsoft Word’s INCLUDEPICTURE field, and that the kit was actively developed and commercialized with updates adding support for newly disclosed CVEs and customization services.
Observed delivery chains evolved across 2017–2018. Early June 2017 chains exploited CVE-2017-0199 to download and execute an HTA file, which then retrieved a decoy document and a malicious VBScript that extracted and ran an embedded executable. That chain installed Smoke Loader, which then downloaded TrickBot, created an empty file named result.exex in %APPDATA% to prevent double infection, and performed cleanup involving Word’s Resiliency registry key. The VBScript only executed the embedded payload when the document was launched from \Downloads, \Desktop, or the Outlook Secure Temp folder. October 2017 variants exploiting CVE-2017-8759 searched \Word\Resiliency\StartupItems registry keys for a value containing .doc to locate the parent document, copied the document to %temp%, extracted an embedded executable and decoy document, overwrote the original document with the decoy, and executed the payload from %APPDATA%\result.exe. One analyzed sample attempted a second check-in using the URI query parameter ?act=hit, and installed the Chthonic banking malware. Later ThreadKit documents using CVE-2017-11882 included the same style of check-in mechanism; one sample executed mshta.exe to retrieve content from hxxps://seliodrones[.]info/vmware/w&\x12\x0cC. After a February 2018 update adding CVE-2018-0802 and CVE-2017-8570, Proofpoint observed a spike in email campaigns using ThreadKit-generated Office attachments. These later chains dropped packager objects into the temporary folder, executed a scriptlet file, and then ran batch files to execute the payload. Placeholder statistics URLs observed in some documents included hxxp://test1[.]ru/newbuild/t.php?stats=send&thread=0 and hxxp://google[.]com/newbuild/t.php?stats=send&thread=0.
ThreadKit has been used to distribute multiple crimeware payloads, including Smoke Loader, TrickBot, Chthonic, FormBook, Loki Bot, and Neutrino Bot. Proofpoint also observed use by more sophisticated financially motivated actors, including the Cobalt Gang. Morphisec described a “Cobalt Gang 1.0” cluster as using the ThreadKit framework extensively, while noting that later Cobalt activity borrowed only some ThreadKit functionality. Reported targeting associated with Cobalt activity included banks, with attacks attributed to the group affecting more than 100 banks across 40 countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit-kit generation/builder framework used to create obfuscated JavaScript-based delivery components; in this campaign, the JavaScript dropper shares functionality with the ThreadKit builder and is used in multi-stage payload delivery.
A Microsoft Office exploit document builder kit used to generate weaponized Office/RTF documents that exploit multiple CVEs (e.g., CVE-2017-0199, CVE-2017-8759, CVE-2017-11882, CVE-2017-8570, CVE-2018-0802) to execute scripts (HTA/VBS/PowerShell/scriptlets/batch) and ultimately run embedded or downloaded payloads. Includes an infection-statistics check-in mechanism to C2 (e.g., via Word INCLUDEPICTURE field).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.