Researchers uncovered a targeted multi-stage malware campaign that compromised victims through watering hole attacks and exploitation of CVE-2018-8174, a zero-day VBScript use-after-free flaw triggered through Internet Explorer’s rendering engine. The exploit chain, previously documented as being deliverable through malicious Office content that forced mshtml.dll to load remote HTML and obfuscated VBScript, enabled shellcode execution and helped attackers install a downloader followed by a custom backdoor dubbed SLUB.
Once deployed, SLUB used legitimate cloud and collaboration services to hide command-and-control and data theft activity. The malware retrieved commands from a GitHub Gist, sent execution results to private Slack channels using embedded API tokens, and uploaded stolen files to file.io. Trend Micro said the downloader also checked for antivirus processes and exploited CVE-2015-1701 for local privilege escalation, while the backdoor persisted via a Run registry key and rundll32.exe. The operation appeared focused on collecting person-related information and communications data, including content from Skype, KakaoTalk, Twitter, bulletin board systems, and HWP documents; GitHub and Slack removed the malicious infrastructure after notification.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Trend Micro found that by 2020 the operators had updated SLUB to replace Slack with attacker-controlled Mattermost infrastructure, creating per-victim channels and uploading command output and screenshots. The report traced older Mattermost-based samples to February 28, 2020, and indicated the malicious Mattermost server was set up on March 10, 2020, as part of Operation Earth Kitsune.
The first victims of the SLUB campaign were observed on February 27 after watering hole attacks redirected visitors into an infection chain exploiting CVE-2018-8174. The malware then gathered host context and began collecting user files and communications data.
Researchers estimated that the attackers compiled the malware on February 22. The campaign used a downloader followed by a custom C++ backdoor dubbed SLUB.
On February 20, the attackers created the Slack workspace used for malware communications and added the first commands to GitHub. SLUB later used embedded Slack API tokens to post results to private channels.
The operators behind the SLUB malware campaign created the GitHub account used for command retrieval on February 19. The campaign later used a GitHub Gist as part of its command-and-control workflow.
The attackers tested the malware on February 23 and 24 before broader victim activity was observed. The campaign used GitHub for commands and Slack for exfiltration and operator communications.
Microsoft had already patched CVE-2018-8174 in May 2018 before the later SLUB campaign used it for initial compromise. The flaw affected VBScript via the Internet Explorer rendering engine.
A malicious sample exploiting CVE-2018-8174 was uploaded to VirusTotal on April 18, 2018. The exploit chain used a Microsoft Word document to fetch remote HTML containing VBScript that triggered the vulnerability.
Kaspersky reported that the CVE-2018-8174 VBScript zero-day was found in the wild in late April 2018 and was reportedly used by an APT actor. Microsoft later confirmed the issue as CVE-2018-8174 after receiving the report.
Trend Micro publicly described the previously unknown multi-stage SLUB malware campaign, including its watering hole delivery, use of CVE-2018-8174 and CVE-2015-1701, and abuse of GitHub, Slack, and file.io for operations. The report also detailed the attackers' focus on person-related information, Skype data, and HWP documents.
After notification from researchers, GitHub and Slack removed the malicious infrastructure used by the SLUB campaign. This disrupted the attackers' communications channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.trendmicro.com
Open sourcesecurelist.com
Open sourceportal.msrc.microsoft.com
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.