A South Korea-aligned espionage group tracked as APT-C-60 exploited a high-severity remote code execution flaw in WPS Office for Windows, CVE-2024-7262, to target users in East Asia. ESET said the attackers used a malicious MHTML spreadsheet containing a hidden hyperlink and a spreadsheet-like lure image to trick victims into interaction, after which WPS Spreadsheet automatically downloaded a remote library and executed arbitrary code. The observed final payload was a custom espionage backdoor dubbed SpyGlace, and separate reporting from DBAPPSecurity confirmed exploitation against users in China.
During its investigation, ESET found that Kingsoft’s initial fix did not fully resolve the issue and uncovered a second related arbitrary code execution vulnerability, CVE-2024-7263, tied to improper input validation. Both flaws were reported to Kingsoft through coordinated disclosure, and the vendor acknowledged and patched the vulnerabilities. The case highlights active in-the-wild exploitation of WPS Office as an espionage entry point, with attackers chaining document-based social engineering and remote library loading to compromise Windows systems.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Kingsoft acknowledged both high-severity WPS Office vulnerabilities and released patches for them. The issues were assigned CVE-2024-7262 and CVE-2024-7263.
During the coordinated disclosure process, DBAPPSecurity independently published an analysis of the weaponized vulnerability. It confirmed that APT-C-60 had exploited the flaw to deliver malware to users in China.
ESET disclosed CVE-2024-7262 and CVE-2024-7263 to Kingsoft through a coordinated disclosure process. The report covered both the original exploit path and the second path found during patch analysis.
After analyzing Kingsoft's initial patch, ESET discovered a second exploitation path caused by improper input validation and tracked it as CVE-2024-7263. This showed the original flaw had not been fully remediated.
Kingsoft issued an initial silent patch for the WPS Office vulnerability. ESET's later review found that this fix did not fully correct the underlying issue.
While investigating the APT-C-60 campaign, ESET Research identified the WPS Office for Windows arbitrary code execution flaw later tracked as CVE-2024-7262. Its analysis tied the exploit activity to the group through a suspicious spreadsheet referencing one of APT-C-60's downloader components.
ESET found that the South Korea-aligned espionage group APT-C-60 exploited the WPS Office for Windows remote code execution vulnerability CVE-2024-7262 in attacks targeting users in East Asia. The attack chain used a malicious MHTML spreadsheet and ultimately deployed the SpyGlace backdoor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceeset.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.