FireEye recently identified a vulnerability – CVE-2017-0199 – that
allows a malicious actor to download and execute a Visual Basic script
containing PowerShell commands when a user opens a Microsoft Office
RTF document containing an embedded exploit. We worked with Microsoft
and href="https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199-hta-handler.html">published
the technical details of this vulnerability as soon as a patch
was made available.
In this follow-up post, we discuss some of the campaigns we observed
leveraging the CVE-2017-0199 zero-day in the days, weeks and months
leading up to the patch being released.
FireEye assesses with moderate confidence that CVE-2017-0199 was
leveraged by financially motivated and nation-state actors prior to
its disclosure. Actors leveraging FINSPY and LATENTBOT used the
zero-day as early as January and March, and similarities between their
implementations suggest they obtained exploit code from a shared
source. Recent DRIDEX activity began following a disclosure on April
7, 2017.
As early as Jan. 25, 2017, lure documents referencing a
Russian Ministry of Defense decree and a manual allegedly published in
the "Donetsk People's Republic" exploited CVE-2017-0199 to
deliver FINSPY payloads. Though we have not identified the targets,
FINSPY is sold by Gamma Group to multiple nation-state clients, and we
assess with moderate confidence that it was being used along with the
zero-day to carry out cyber espionage.
The malicious document, СПУТНИК