Attackers used CVE-2017-0199 in malicious Microsoft Word and RTF documents to trigger the hta handler and pull follow-on payloads from attacker-controlled infrastructure, enabling code execution without relying on macros. One observed chain used a fake invoice attachment disguised as a .doc file to fetch a malicious HTA, then downloaded a Remcos RAT installer and an AutoIt-based persistence component over HTTPS from streetsave[.]club and regwide[.]club; the infected host later communicated with darlz.freeddns[.]org on port 1695.
Separate in-the-wild activity documented the same exploit delivering Visual Basic script stages that killed winword.exe, retrieved a payload disguised as an image, copied it as a Startup-folder winword.exe, and opened a decoy document to hide the intrusion. Researchers linked final payloads to WingBird and FinFisher-like malware, while other malicious documents delivered LATENTBOT; the campaigns relied on obfuscation, anti-analysis techniques, and persistence through registry Run keys or Startup-folder placement, underscoring the need to patch vulnerable Office systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After execution, the infected host downloaded additional payloads from streetsave[.]club and regwide[.]club, installed a Remcos RAT component, and used an AutoIt-based persistence mechanism. The compromised system then communicated with darlz.freeddns[.]org over port 1695 and created persistence-related registry keys including a Run key named "WindowsUpdate."
A malspam campaign dated 2017-12-21 sent an email with subject "Invoice" and an attachment named "Proforma invoice.doc" that was actually an RTF exploiting CVE-2017-0199. The exploit chain retrieved a malicious HTA file and led to delivery of Remcos RAT.
The analyzed CVE-2017-0199 infection chain terminated winword.exe to hide prompts, downloaded a payload disguised as copy.jpg, saved it as a Startup-folder winword.exe for persistence, and opened a decoy document to mask the compromise. The final payload was assessed as a WingBird dropper variant with similarities to FinFisher and anti-analysis protections including a custom virtual machine.
FireEye observed in-the-wild exploitation of CVE-2017-0199 in Microsoft Word using malicious documents that linked to attacker-controlled servers. Two documents were noted as successfully executing payloads, one delivering LATENTBOT and another delivering WingBird/FinFisher.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcemalware-traffic-analysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.