A phishing campaign used purchase-order themed emails and a malicious Excel attachment to infect Windows systems with SmokeLoader, abusing the long-patched Microsoft Office vulnerabilities CVE-2017-0199 and CVE-2017-11882. Researchers said the spreadsheet hid its next stage in an encrypted OLE stream protected with Excel's default password, "VelvetSweatshop," then retrieved a disguised RTF file named receipt.doc that exploited the Microsoft Equation Editor flaw to continue execution.
After exploitation, the malware downloaded and launched SmokeLoader as vbc.exe, then repeatedly contacted a remote URL to fetch a GZip-compressed payload disguised as a JPG image. That payload decompressed into an obfuscated .NET DLL believed to be zgRAT, showing how attackers are still chaining older Office exploits and commodity loaders to deliver remote-access malware years after fixes for the vulnerabilities were released.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A phishing email themed around a purchase order used the attachment "Purchase Order FG-20220629.xlsx" to begin the infection chain. The filename anchors the lure to 2022-06-29, and the message targeted a webmail address at a large telecommunications company in Taiwan.
A CVE record exists for CVE-2017-0199, one of the Microsoft Office vulnerabilities later used in the analyzed infection chain.
The Fortinet report states that SmokeLoader, also known as Dofoil, has existed in some form since 2011.
Fortinet published analysis of a recent Windows infection chain in which an Excel lure exploited CVE-2017-0199 to fetch an RTF file exploiting CVE-2017-11882, which then downloaded SmokeLoader. The report assessed the final payload as a likely zgRAT sample and highlighted continued abuse of long-patched vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.