A phishing campaign is using emails disguised as payment or money transfer confirmations to trick recipients into opening a malicious XLS attachment. The messages impersonate employees of a specific company in Korea and present the spreadsheet as a legitimate payment slip, using a financial transaction lure to increase the likelihood that targets will open the file.
When opened, the attachment exploits CVE-2017-0199 in Microsoft Office to retrieve a remote HTA payload. The HTA then uses WMI Win32_Process.Create() to launch an obfuscated PowerShell script that downloads a steganographic PNG file, extracts and decrypts an in-memory .NET loader from embedded Base64 data, and ultimately installs Remcos RAT. The malware gives attackers remote access, including command execution, keylogging, screen capture, file manipulation, and data exfiltration to command-and-control infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
AhnLab Security intelligence Center (ASEC) reported a phishing campaign in which emails impersonate employees of a company in Korea and pose as payment or money transfer confirmation notices. The emails carry a malicious XLS attachment that exploits CVE-2017-0199 to deliver a multi-stage infection ending in Remcos RAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.