Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
Remcos RAT phishing campaign disguised as project material (TL-2026-2764) is a high-severity malware campaign scored CVSS 7.8, first published 2026-09-28. It has no confirmed attribution, affects Microsoft Office, references 1 CVE (CVE-2017-0199), maps to 15 MITRE ATT&CK techniques (T1027, T1027.003, T1047), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2764
- Threat ID
- TL-2026-2764
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- corporate, procurement, manufacturing
- Target regions
- south korea
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Remcos RAT phishing campaign disguised as project material
Malware and tooling: .NET loader (Base64-embedded in PNG), Remcos, Remcos
AhnLab ASEC reports phishing emails impersonating employees of a Korean company and posing as project material purchase requests. A malicious XLS attachment exploits CVE-2017-0199 to fetch an HTA file that runs obfuscated PowerShell, pulls a steganographic PNG, extracts a Base64 .NET loader and deploys Remcos RAT. No threat actor attribution is given.
How Remcos RAT phishing campaign disguised as project material works
On 2026-09-28 AhnLab Security Intelligence Center (ASEC) documented a phishing campaign in which emails impersonate employees of a specific company in Korea and present themselves as project material purchase requests. The attached XLS is disguised as a project material purchase request form and shows legitimate-looking purchase content as a decoy to lower the recipient's suspicion.
When the XLS is opened it exploits CVE-2017-0199, an OLE2Link handling flaw in Microsoft Office/WordPad, to download an HTA file from an attacker-hosted server (hxxp://172.245.209.133/70/Weprovideforbesthingstocomebackgoodthings.Hta). The HTA executes obfuscated PowerShell in the background through WMI Win32_Process.Create(). The decoded PowerShell downloads a steganographic PNG from a Cloudflare Workers hosted URL (muddy-sound-e0cd.nodetectonn.workers.dev/HIsPq), locates a Base64-encoded .NET loader embedded in the image using the marker strings "IN-" and "-inl", decodes it and loads it into memory, passing the C2 address as an argument.
The .NET loader then downloads and executes the Remcos RAT payload (served from the same IP as Img_201031.Png). Remcos connects to the dynamic-DNS C2 blessedongrace.duckdns.org on TCP port 19700 and receives and executes remote commands, with keylogging, screen capture, file manipulation and system/user information collection; collected data is sent to the C2.
The technique chain (malicious Excel, CVE-2017-0199, HTA, multi-layer scripting, in-memory Remcos) resembles the fileless Remcos variant Fortinet reported in November 2024 (HTA cookienetbookinetcahce.hta from 192.3.220.22, purchase-order lure), but ASEC does not link the two campaigns or attribute this activity to any actor. ASEC has also published a structurally similar Remcos campaign (Excel lure, CVE-2017-0199, HTA, PowerShell, steganographic PNG, .NET loader) using different infrastructure; no infrastructure overlap with this campaign was identified. CVE-2017-0199 was patched by Microsoft in April 2017 and is listed in the CISA KEV catalog; unpatched Office installations remain exposed. Severity is analyst-assigned; the CVSS score shown is the NVD 3.1 base score for CVE-2017-0199, not for the campaign.
MITRE ATT&CK techniques used in TL-2026-2764
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1620 Reflective Code Loading; T1684.001 Impersonation
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1203 Exploitation for Client Execution; T1204.002 Malicious File
Collection
T1056.001 Keylogging; T1113 Screen Capture
Discovery
T1082 System Information Discovery
Initial Access
T1566.001 Spearphishing Attachment
Command and Control
Affected products and versions in Remcos RAT phishing campaign disguised as project material
- Microsoft — Office
Vulnerable versions: 2007 SP3; 2010 SP2; 2013 SP1; 2016
Fixed in: Apply Microsoft update per MSRC advisory for CVE-2017-0199 - Microsoft — Windows (WordPad)
Vulnerable versions: Vista SP2; 7 SP1; Server 2008 SP2; Server 2012
Fixed in: Apply Microsoft update per MSRC advisory for CVE-2017-0199
Remediation for Remcos RAT phishing campaign disguised as project material
Patches
- Apply the Microsoft security update for CVE-2017-0199 (April 2017, see MSRC advisory) on all Office and WordPad installations
Immediate actions
- Block 172.245.209.133, muddy-sound-e0cd.nodetectonn.workers.dev and blessedongrace.duckdns.org (TCP/19700) at proxy, DNS and firewall
- Hunt for mshta.exe or powershell.exe spawned by EXCEL.EXE or via WMI Win32_Process.Create, and for the listed MD5 hashes
- Quarantine XLS attachments in mail that impersonate purchase or procurement requests from internal-looking senders
- Search proxy logs for requests to /70/Img_201031.Png, /70/Weprovideforbesthingstocomebackgoodthings.Hta and workers.dev /HIsPq
Workarounds
- Open attachments only in Protected View / Application Guard and block external OLE object linking in Office where the patch cannot be applied
Longer-term hardening
- Train staff to verify unexpected purchase-request attachments through a second channel
- Restrict or alert on mshta.exe execution and outbound connections to dynamic-DNS domains
- Enable EDR behavioral detection for Office spawning script hosts and for in-memory .NET assembly loading
CVEs associated with Remcos RAT phishing campaign disguised as project material
Timeline of Remcos RAT phishing campaign disguised as project material
- Microsoft releases the security update for CVE-2017-0199 in April 2017 Patch Tuesday; the flaw had already been exploited in the wild to deliver malware such as Dridex
- CVE-2017-0199 (Microsoft Office/WordPad OLE object remote code execution) published in NVD; CVSS 3.1 base score 7.8
- CISA adds CVE-2017-0199 to the Known Exploited Vulnerabilities catalog
- CISA KEV remediation due date for CVE-2017-0199 for federal agencies
- Fortinet FortiGuard reports a purchase-order phishing campaign using malicious Excel and CVE-2017-0199 to deliver a fileless Remcos RAT variant via the HTA cookienetbookinetcahce.hta hosted at 192.3.220.22
- NVD record for CVE-2017-0199 last modified, listing Office 2007 SP3 to 2016 and Windows Vista SP2 to Server 2012 among affected products
- AhnLab ASEC publishes analysis of Remcos RAT phishing emails posing as project material purchase requests targeting Korean company employees, with 3 MD5 hashes and C2 indicators
Sources cited for Remcos RAT phishing campaign disguised as project material
- Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests (AhnLab ASEC)
- NVD - CVE-2017-0199
- Microsoft MSRC advisory - CVE-2017-0199
- CISA Known Exploited Vulnerabilities Catalog
- Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT (The Hacker News)
- A new fileless variant of Remcos RAT observed in the wild (Security Affairs)
- New Remcos RAT Activity Detection: Phishing Campaign Spreading a Novel Fileless Malware Variant (SOC Prime)
- Beware of Phishing Emails Disguised as Money Transfer Confirmations (AhnLab ASEC)
- Microsoft Patch Tuesday fixes three flaws actively exploited in attacks in the wild (Security Affairs)
- CVE-2017-0199 coverage (Cisco Talos)
More in malware
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)
Detection coverage for TL-2026-2764
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2764 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.