Security researchers reported a phishing campaign using a PDF attachment named "REMMITANCE INVOICE.pdf" to deliver Snake Keylogger through a multi-stage infection chain. The PDF carried an embedded Word document that appeared trustworthy, and the document then retrieved a remote template or RTF file from attacker-controlled infrastructure. That RTF contained malformed OLE content exploiting the Microsoft Equation Editor flaw CVE-2017-11882, allowing shellcode to run and download the final Windows payload, identified in reporting as vbc.exe or fresh.exe and linked to Snake Keylogger.
Analysts said the campaign relied on layered evasion, including hiding a malicious DOCX inside a PDF, hosting the exploit remotely, and decrypting shellcode in memory before execution. The final malware was described as a modular information stealer capable of credential theft, persistence, defense evasion, data collection, and exfiltration over SMTP. Researchers highlighted that the attack demonstrates the continued effectiveness of the long-patched CVE-2017-11882 vulnerability and advised defenders to analyze suspicious files with dedicated tooling rather than opening them in PDF or Office applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported on HP Wolf Security's findings about a PDF-based malware campaign that smuggled an embedded Word document to trigger a CVE-2017-11882 exploit and install Snake Keylogger. The coverage highlighted continued abuse of the long-patched Equation Editor flaw in the wild.
HP Wolf Security reported a malware campaign using emailed PDF attachments to deliver an embedded Word document and a remote RTF exploit chain. Its analysis linked the malformed OLE objects to CVE-2017-11882 and identified the final payload fresh.exe as Snake Keylogger.
NVISO Labs published an analysis of the multilayer malicious document chain, showing that the PDF embedded a DOCX, the DOCX fetched a malformed RTF, and shellcode in an embedded OLE object downloaded a Windows executable. The analysis identified the final malware as Snake Keylogger and later tied the exploit stage to CVE-2017-11882.
Microsoft fixed CVE-2017-11882, a remote code execution vulnerability in Microsoft Equation Editor. Later reporting on the Snake Keylogger campaign identified this flaw as the exploit used in the malicious RTF stage.
In the observed campaign, attackers sent email messages with a PDF attachment named "REMMITANCE INVOICE.pdf" or "Remittance Invoice" that embedded a Word document. The DOCX used an external relationship to fetch a remote RTF file, which exploited CVE-2017-11882 and led to download of a Snake Keylogger payload identified as fresh.exe or vbc.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethreatresearch.ext.hp.com
Open sourceblog.nviso.eu
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.