Skip to content
July 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Zyklon Malware spreads through Microsoft Office vulnerabilities
  • Malware

Zyklon Malware spreads through Microsoft Office vulnerabilities

Do Son January 18, 2018 4 minutes read
Add Daily CyberSecurity as a preferred source on Google

Zyklon malware is using three Microsoft Office vulnerability for spreading. An attacker telecommunications, insurance, and financial services companies. According to FireEye researchers said the attackers are trying to collect passwords and encryption currency wallet data and for the possible future DDoS attacks collection target list.

The researchers said the attack started with spamming activity by sending a malicious ZIP file containing one of several types of DOC files that eventually took advantage of one of three Microsoft Office vulnerabilities.

The first vulnerability is Microsoft patched last October .NET Framework error (the CVE-2017-8759 ). Microsoft said the goal of opening infected documents allowed attackers to install programs, process data and create new privileged accounts. In the case of an attack described by FireEye, the infected DOC file contains an embedded OLE object that, when executed, triggers the download of additional DOC files from the stored URL. In mid-September 2017, the .NET Framework 0Day Vulnerability CVE-2017-8759, which has been used by attackers to distribute FinFisher malware

The second vulnerability ( CVE-2017-11882 ) was a 17-year remote code execution error found in an Office executable named Microsoft Formula Editor. This bug has been patched as part of Microsoft’s November 2017 Patch Tuesday release. Like previous vulnerabilities, victims who opened a specially crafted DOC automatically downloaded additional DOC files that contained PowerShell commands for downloading the final payload. At the end of November 2017, the Office Memory Corruption Vulnerability, cve-2017-11882, has been exploited in the wild, with Cobalt in action.

Microsoft does not consider the third vulnerability to be a hole in Dynamic Data Exchange (DDE). Instead, it insists DDE is a product feature. However, in November, it released instructions to administrators about how to safely disable this feature through the new Office registry settings. In mid-October 2017, DDE attacks do not require macros to be enabled and malware can be executed in Office applications, and FIN7 financial hackers are already in action

DDE is a protocol that establishes how applications send messages and share data through shared memory.However, over the past year, attackers have had great success using macro-based malware to leverage DDE to launch Dropper, vulnerabilities, and malware.

In a recent attack, FireEye said DDE was also used to download a Dropper.

 

The researchers wrote:

“In all these techniques, the same domain is used to download the next level payload (Pause.ps1), which is another PowerShell script that is Base64 encoded

The Pause.ps1 script is responsible for resolving the APIs required for code injection. Ultimately, Pause.ps1 acts as another dropper to deliver the final “core payload.”

FireEye wrote:

“Zyklon is a publicly available, full-featured backdoor capable of keylogging, password harvesting, downloading and executing additional plugins, conducting distributed denial-of-service (DDoS) attacks, and self-updating and self-removal. The malware can download several plugins, some of which include features such as cryptocurrency mining and password recovery, from browsers and email software.”

In this case, Zyklon can also communicate with its command and control C&C server over the Tor network. The researchers said.

“The Zyklon executable contains another encrypted file in its .Net resource section named tor. This file is decrypted and injected into an instance of InstallUtiil.exe, and functions as a Tor anonymizer”

The researchers said such malware can be used to perform many different tasks, including downloading new plug-ins, stealing passwords, or opening a proxy and establishing an inverted Socks5 proxy on the infected host. FireEye said.

“These types of threats show why it is very important to ensure that all software is fully updated. Additionally, all industries should be on alert, as it is highly likely that the threat actors will eventually move outside the scope of their current targeting.”

Source: threatpost

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Hacker group threatens to expose Nvidia driver and firmware data
  • SharePoint Shadow: Havoc’s FUD Malware Conceals Cyber Attacks
  • Lazarus Subgroup Deploys Three Custom RATs in Targeted Crypto Attacks
  • PipeMagic Trojan Exploits Fake ChatGPT App to Target Saudi Arabian Organizations
  • Ongoing Phishing Attack in LATAM Region
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Zyklon Malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intel📅 Updated: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-13439CVSS 9.8
    The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to...
  • CVE-2026-64625CVSS 9.8
    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps...
  • CVE-2026-53595CVSS 9.4
    FreeScout is a free help desk and shared inbox built with PHP's...
  • CVE-2026-44231CVSS 9.1
    RT is an open source, enterprise-grade issue and ticket tracking system. Versions...
  • CVE-2026-63766CVSS 9.8
    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where...
  • CVE-2026-63767CVSS 9.8
    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization...
  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
  • CVE-2026-35048CVSS 9.8
    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.