Recently, Microsoft users were informed by the company about a new campaign that is currently underway. This particular campaign exploits a flaw found in 2017 to introduce a Trojan onto victims' machines.

Microsoft said in a Twitter post that the flaw, codenamed CVE-2017-11882, was patched in 2017. However, there have been unexpected developments due to the flaw, such as spam emails in European languages that carry malware RTF files. This requires, according to the company, frequent security updates.
The company explained in detail the steps that are taken through this process. So according to Microsoft, the RTF file downloads and runs multiple scripts of different types (VBScript, PowerShell, PHP) to download the payload. The backdoor then tries to connect to a malicious domain that is currently not running. Even if this domain is not running, hackers can update the attack in the future. This is how additional payloads are downloaded, which will lead to ransomware or trojans, information theft, etc.
The Redmond security team also reported that: “Office 365 ATP detects the emails and attachments used in this campaign. Windows Defender ATP detects the documents as Exploit: O97M/CVE-2017-11882.AD and the payload as Trojan: MSIL/Cretasker.”
The software bug in question, which exists in the Microsoft Office editor, has been popular since it was discovered a few years ago, as it does not require user interaction to do the job it is intended to do.
It was initially used by APT34, an Iranian espionage , and last week it was detected on other targets with great frequency.
