Targeted threat actors used malicious Microsoft Office documents exploiting CVE-2012-0158 to compromise victims in long-running espionage campaigns, including Tibetan organizations and primarily Russian-speaking individuals. Citizen Lab reported that trojanized Word attachments in 2012 and 2013 delivered the Surtr malware family, while Symantec documented the Scarab group using spearphishing emails, compressed archives, and later .scr droppers to install Trojan.Scieron and Trojan.Scieron.B on a small number of carefully selected systems each month.
The malware families provided persistent backdoor and surveillance capabilities after infection. Surtr injected into explorer or iexplore, stored campaign and command-and-control data in the registry, and supported file listing, USB enumeration, web cache viewing, remote command execution, and keylogging, with observed C2 including internet.3-a.net on port 9696 and a second-stage payload named x86_GmRemote.dll. Scieron acted as a downloader and backdoor, while Scieron.B added stronger remote access features and a rootkit-like component to hide some network activity; Symantec said Scarab’s infrastructure relied on dynamic DNS and C2 servers commonly hosted in South Korea. The campaigns showed that the widely exposed Microsoft Windows Common Controls ActiveX flaw affected numerous Microsoft products and remained a practical delivery vector for tailored espionage operations.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
The SecurityFocus/Bugtraq record for CVE-2012-0158 lists a last update date of September 25, 2017. This reflects a later update to the vulnerability entry rather than a new exploitation event.
From January 2014 onward, Scarab used .scr files, often with Russian-language titles, to drop Trojan.Scieron. This represented a delivery change from the earlier malicious document droppers.
Symantec reported that Scarab continued to send malicious .doc droppers intermittently until August 2013. These documents included exploits for older patched vulnerabilities such as CVE-2012-0158.
Citizen Lab analyzed a malicious email sent to Tibetan organizations in June 2013 that impersonated a prominent community member and carried three trojanized Word attachments. The attachments were actually RTF files exploiting CVE-2012-0158 to deliver the Surtr malware family.
From April 2013 until at least January 2014, Scarab used finance- and G20-related lures against targets including a European government, an international economic organization, and a European government's economic ministry. This marked an evolution from earlier academic and generic themes.
Citizen Lab noted that the malicious template used in Surtr attacks was created in March 2013. The template used the Chartspace Office Web Component to trigger code execution via CVE-2012-0158.
Seven days after the January 22 email, Scarab sent another phishing email to the same two individuals with the Russian-language subject “Информация по обслуживанию высвобожденны.” This showed continued follow-up targeting of the same victims.
On January 22, 2013, Scarab sent an email with the subject “Joint Call For Papers - Conferences / Journal Special Issues, January 2013” to two individuals associated with an Australian-funded academic research project. The lure reflected the group's earlier academic-themed targeting.
Citizen Lab reported that it had observed Surtr used in attacks on Tibetan groups dating back to November 2012. This established the malware family's use before the later June 2013 campaign it analyzed in detail.
On October 29, 2012, Scarab sent a Russian-language phishing email with the subject “Экспериментальное определение эффективно” to two individuals working for a large retail organization. The message was part of the group's targeted spearphishing activity.
Symantec observed that a number of Scarab phishing emails began being blocked by Symantec .Cloud starting in October 2012. The blocked messages were sent from @yandex.ru email addresses.
Citizen Lab found that the domain internet.3-a.net resolved to 184.82.123.143 in May 2012, the same IP as android.uyghur.dnsd.me. Citizen Lab had previously documented android.uyghur.dnsd.me as Android malware command-and-control infrastructure targeting the Tibetan community.
Citizen Lab stated that Microsoft released a patch for CVE-2012-0158. This patch predated later phishing campaigns that continued to exploit the vulnerability.
The Microsoft Windows Common Controls ActiveX Control remote code execution vulnerability, tracked as CVE-2012-0158, was published in SecurityFocus as Bugtraq ID 52911. The entry described it as a remotely exploitable design error affecting a wide range of Microsoft products.
Symantec assessed that the Scarab espionage campaign had targeted primarily Russian-speaking individuals inside and outside Russia since at least January 2012. The group used highly targeted phishing and custom malware rather than broad enterprise compromises.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 56 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcecommunity.broadcom.com
Open sourcesecurityfocus.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.