A phishing campaign is using emails disguised as payment or money transfer confirmations to trick recipients into opening a malicious XLS attachment. The messages impersonate employees of a specific company in Korea and present the spreadsheet as a legitimate payment slip, using a financial transaction lure to increase the likelihood that targets will open the file.
When opened, the attachment exploits CVE-2017-0199 in Microsoft Office to retrieve a remote HTA payload. The HTA then uses WMI Win32_Process.Create() to launch an obfuscated PowerShell script that downloads a steganographic PNG file, extracts and decrypts an in-memory .NET loader from embedded Base64 data, and ultimately installs Remcos RAT. The malware gives attackers remote access, including command execution, keylogging, screen capture, file manipulation, and data exfiltration to command-and-control infrastructure.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
AhnLab Security intelligence Center (ASEC) reported a phishing campaign in which emails impersonate employees of a company in Korea and pose as payment or money transfer confirmation notices. The emails carry a malicious XLS attachment that exploits CVE-2017-0199 to deliver a multi-stage infection ending in Remcos RAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.