Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies

Remcos RAT phishing campaign disguised as project material (TL-2026-2764) is a high-severity malware campaign scored CVSS 7.8, first published 2026-09-28. It has no confirmed attribution, affects Microsoft Office, references 1 CVE (CVE-2017-0199), maps to 15 MITRE ATT&CK techniques (T1027, T1027.003, T1047), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2764

Threat ID
TL-2026-2764
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
MALWARE
First published
2026-09-28
Last reviewed
2026-09-28
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
corporate, procurement, manufacturing
Target regions
south korea
Detection rules
9
Indicators of compromise
17

Malware and tooling in Remcos RAT phishing campaign disguised as project material

Malware and tooling: .NET loader (Base64-embedded in PNG), Remcos, Remcos

AhnLab ASEC reports phishing emails impersonating employees of a Korean company and posing as project material purchase requests. A malicious XLS attachment exploits CVE-2017-0199 to fetch an HTA file that runs obfuscated PowerShell, pulls a steganographic PNG, extracts a Base64 .NET loader and deploys Remcos RAT. No threat actor attribution is given.

How Remcos RAT phishing campaign disguised as project material works

On 2026-09-28 AhnLab Security Intelligence Center (ASEC) documented a phishing campaign in which emails impersonate employees of a specific company in Korea and present themselves as project material purchase requests. The attached XLS is disguised as a project material purchase request form and shows legitimate-looking purchase content as a decoy to lower the recipient's suspicion.

When the XLS is opened it exploits CVE-2017-0199, an OLE2Link handling flaw in Microsoft Office/WordPad, to download an HTA file from an attacker-hosted server (hxxp://172.245.209.133/70/Weprovideforbesthingstocomebackgoodthings.Hta). The HTA executes obfuscated PowerShell in the background through WMI Win32_Process.Create(). The decoded PowerShell downloads a steganographic PNG from a Cloudflare Workers hosted URL (muddy-sound-e0cd.nodetectonn.workers.dev/HIsPq), locates a Base64-encoded .NET loader embedded in the image using the marker strings "IN-" and "-inl", decodes it and loads it into memory, passing the C2 address as an argument.

The .NET loader then downloads and executes the Remcos RAT payload (served from the same IP as Img_201031.Png). Remcos connects to the dynamic-DNS C2 blessedongrace.duckdns.org on TCP port 19700 and receives and executes remote commands, with keylogging, screen capture, file manipulation and system/user information collection; collected data is sent to the C2.

The technique chain (malicious Excel, CVE-2017-0199, HTA, multi-layer scripting, in-memory Remcos) resembles the fileless Remcos variant Fortinet reported in November 2024 (HTA cookienetbookinetcahce.hta from 192.3.220.22, purchase-order lure), but ASEC does not link the two campaigns or attribute this activity to any actor. ASEC has also published a structurally similar Remcos campaign (Excel lure, CVE-2017-0199, HTA, PowerShell, steganographic PNG, .NET loader) using different infrastructure; no infrastructure overlap with this campaign was identified. CVE-2017-0199 was patched by Microsoft in April 2017 and is listed in the CISA KEV catalog; unpatched Office installations remain exposed. Severity is analyst-assigned; the CVSS score shown is the NVD 3.1 base score for CVE-2017-0199, not for the campaign.

MITRE ATT&CK techniques used in TL-2026-2764

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1620 Reflective Code Loading; T1684.001 Impersonation

Execution

T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1203 Exploitation for Client Execution; T1204.002 Malicious File

Collection

T1056.001 Keylogging; T1113 Screen Capture

Discovery

T1082 System Information Discovery

Initial Access

T1566.001 Spearphishing Attachment

Command and Control

T1568 Dynamic Resolution

Affected products and versions in Remcos RAT phishing campaign disguised as project material

  • Microsoft — Office
    Vulnerable versions: 2007 SP3; 2010 SP2; 2013 SP1; 2016
    Fixed in: Apply Microsoft update per MSRC advisory for CVE-2017-0199
  • Microsoft — Windows (WordPad)
    Vulnerable versions: Vista SP2; 7 SP1; Server 2008 SP2; Server 2012
    Fixed in: Apply Microsoft update per MSRC advisory for CVE-2017-0199

Remediation for Remcos RAT phishing campaign disguised as project material

Patches

  • Apply the Microsoft security update for CVE-2017-0199 (April 2017, see MSRC advisory) on all Office and WordPad installations

Immediate actions

  • Block 172.245.209.133, muddy-sound-e0cd.nodetectonn.workers.dev and blessedongrace.duckdns.org (TCP/19700) at proxy, DNS and firewall
  • Hunt for mshta.exe or powershell.exe spawned by EXCEL.EXE or via WMI Win32_Process.Create, and for the listed MD5 hashes
  • Quarantine XLS attachments in mail that impersonate purchase or procurement requests from internal-looking senders
  • Search proxy logs for requests to /70/Img_201031.Png, /70/Weprovideforbesthingstocomebackgoodthings.Hta and workers.dev /HIsPq

Workarounds

  • Open attachments only in Protected View / Application Guard and block external OLE object linking in Office where the patch cannot be applied

Longer-term hardening

  • Train staff to verify unexpected purchase-request attachments through a second channel
  • Restrict or alert on mshta.exe execution and outbound connections to dynamic-DNS domains
  • Enable EDR behavioral detection for Office spawning script hosts and for in-memory .NET assembly loading

CVEs associated with Remcos RAT phishing campaign disguised as project material

CVE-2017-0199

Timeline of Remcos RAT phishing campaign disguised as project material

  • Microsoft releases the security update for CVE-2017-0199 in April 2017 Patch Tuesday; the flaw had already been exploited in the wild to deliver malware such as Dridex
  • CVE-2017-0199 (Microsoft Office/WordPad OLE object remote code execution) published in NVD; CVSS 3.1 base score 7.8
  • CISA adds CVE-2017-0199 to the Known Exploited Vulnerabilities catalog
  • CISA KEV remediation due date for CVE-2017-0199 for federal agencies
  • Fortinet FortiGuard reports a purchase-order phishing campaign using malicious Excel and CVE-2017-0199 to deliver a fileless Remcos RAT variant via the HTA cookienetbookinetcahce.hta hosted at 192.3.220.22
  • NVD record for CVE-2017-0199 last modified, listing Office 2007 SP3 to 2016 and Windows Vista SP2 to Server 2012 among affected products
  • AhnLab ASEC publishes analysis of Remcos RAT phishing emails posing as project material purchase requests targeting Korean company employees, with 3 MD5 hashes and C2 indicators

Sources cited for Remcos RAT phishing campaign disguised as project material

More in malware

Detection coverage for TL-2026-2764

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2764 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats