HomeSecurityPhishing campaign combines old Office vulnerability with fileless XWorm RAT

Phishing campaign combines old Office vulnerability with fileless XWorm RAT

Fortinet researchers have uncovered a new phishing campaign that distributes the commercially available XWorm malware, combining a long-standing Microsoft Office vulnerability with fileless execution to evade detection. The campaign, which uses multi-subject phishing emails and a malicious Excel add-in, ultimately deploys the modular remote access trojan (RAT) capable of encrypted command and control (C2) and plugin-based expansion.

See also: APT36 and SideCopy: Cross-system RAT campaigns on Indian entities

XWorm
Phishing campaign combines old Office vulnerability with fileless XWorm RAT

The attackers used a phishing email containing a malicious Excel add-in that exploits CVE-2018-0802, a memory corruption vulnerability in Office that was patched in 2018. The attack continues with HTA-based and PowerShell execution to load additional elements of the attack.

According to a Fortinet blog post, the campaign relies on business-themed phishing baits and the old remote code execution vulnerability in Microsoft Equation Editor that defenders have known about for years. Fortinet noted that the continued success of CVE-2018-0802 suggests that patching gaps remain a viable attack surface.

Jason Soroko, a senior partner at Sectigo, said the combination of routine phishing with modern technical support is what makes the campaign remarkable. “What stands out here is how ‘old’ and ‘routine’ the front end is, and how modern the back end remains,” he said.

Fortinet researchers added that the remote code privileges gained through CVE-2018-0802 further allow execution of HTA and PowerShell components, keeping much of the activity off-disk.

See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

Phishing campaign combines old Office vulnerability with fileless XWorm RAT
Phishing campaign combines old Office vulnerability with fileless XWorm RAT

“This combination is a reminder that patch hygiene and macro or script execution policy do even more real work than most organizations care to admit,” Soroko added. Beyond the initial access, Fortinet observed a fileless .NET stage that was loaded directly into memory, followed by a hollowing process in msbuild.exe, a legitimate Microsoft build tool capable of executing .NET code.

The choice of msbuild.exe aligns with the malware's execution requirements while helping it integrate into normal system activity. Once activated, XWorm communicates with its C2 using an AES-encrypted packet, which supports a broad ecosystem of plugins.

This modularity, the researchers noted, extends its capabilities beyond remote access, allowing for credential theft, data extraction, disruption, and modernization paths depending on what the operator wants.

See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

Phishing campaign combines old Office vulnerability with fileless XWorm RAT
Phishing campaign combines old Office vulnerability with fileless XWorm RAT

The disclosure also included indicators of compromise associated with the campaign, including phishing URLs and domains used to host HTA files and loaders, the C2 server, file hashes for the malicious Excel attachment, and the final XWorm payload.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS