Fortinet researchers have uncovered a new phishing campaign that distributes the commercially available XWorm malware, combining a long-standing Microsoft Office vulnerability with fileless execution to evade detection. The campaign, which uses multi-subject phishing emails and a malicious Excel add-in, ultimately deploys the modular remote access trojan (RAT) capable of encrypted command and control (C2) and plugin-based expansion.
See also: APT36 and SideCopy: Cross-system RAT campaigns on Indian entities

The attackers used a phishing email containing a malicious Excel add-in that exploits CVE-2018-0802, a memory corruption vulnerability in Office that was patched in 2018. The attack continues with HTA-based and PowerShell execution to load additional elements of the attack.
According to a Fortinet blog post, the campaign relies on business-themed phishing baits and the old remote code execution vulnerability in Microsoft Equation Editor that defenders have known about for years. Fortinet noted that the continued success of CVE-2018-0802 suggests that patching gaps remain a viable attack surface.
Jason Soroko, a senior partner at Sectigo, said the combination of routine phishing with modern technical support is what makes the campaign remarkable. “What stands out here is how ‘old’ and ‘routine’ the front end is, and how modern the back end remains,” he said.
Fortinet researchers added that the remote code privileges gained through CVE-2018-0802 further allow execution of HTA and PowerShell components, keeping much of the activity off-disk.
See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

“This combination is a reminder that patch hygiene and macro or script execution policy do even more real work than most organizations care to admit,” Soroko added. Beyond the initial access, Fortinet observed a fileless .NET stage that was loaded directly into memory, followed by a hollowing process in msbuild.exe, a legitimate Microsoft build tool capable of executing .NET code.
The choice of msbuild.exe aligns with the malware's execution requirements while helping it integrate into normal system activity. Once activated, XWorm communicates with its C2 using an AES-encrypted packet, which supports a broad ecosystem of plugins.
This modularity, the researchers noted, extends its capabilities beyond remote access, allowing for credential theft, data extraction, disruption, and modernization paths depending on what the operator wants.
See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

The disclosure also included indicators of compromise associated with the campaign, including phishing URLs and domains used to host HTA files and loaders, the C2 server, file hashes for the malicious Excel attachment, and the final XWorm payload.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
