Hackers Hijack Microsoft Flaw to Unleash Stealthy XLoader Malware Attack

A sophisticated phishing campaign exploiting a nearly 8-year-old Microsoft Office vulnerability to distribute the dangerous XLoader information stealer. The attack leverages CVE-2017-11882, a memory corruption vulnerability in Microsoft’s Equation Editor component, demonstrating that cybercriminals continue to successfully weaponize older security flaws. Phishing Campaign Exploits Equation Editor Vulnerability (CVE-2017-11882) The attackers are sending phishing emails disguised as purchase or order confirmations, prompting recipients to open attached DOCX files to verify transaction details. A harmless document actually contains a malicious RTF file that triggers the equation editor vulnerability. “These emails trick recipients into opening a DOCX attachment that secretly contains a malicious RTF file exploiting a known vulnerability (CVE-2017-11882) in Microsoft’s Equation Editor,” explained ASEC researchers.

XLoader Malware Resurfaces Through Legacy Microsoft Office Flaw in Stealthy Phishing Wave

A new wave of phishing attacks is exploiting a long-forgotten Microsoft Office weakness—originally disclosed nearly eight years ago—to stealthily deploy the XLoader infostealer.

Threat actors are weaponizing CVE-2017-11882, a memory-handling bug in Microsoft’s deprecated Equation Editor, proving that aging vulnerabilities remain lucrative targets when organizations delay patching.

Disguised as routine business emails—like order confirmations or purchase notices—these phishing messages urge recipients to open seemingly innocent DOCX attachments. Beneath the surface, however, lurks a malicious RTF payload embedded within the DOCX file. Once opened, the file silently triggers the legacy vulnerability and executes malicious code without the user’s knowledge.

According to researchers at ASEC, this technique allows attackers to bypass many modern security defenses by relying on overlooked, outdated components still lingering in enterprise environments.

Malicious Email Lures Kick Off Exploit Chain

The infection process is set in motion as soon as the victim opens the attached DOCX file. This document initiates an external request to fetch and run a concealed RTF payload.

Once activated, the RTF drops a script file named Client.vbe into a temporary directory. Leveraging the long-known Equation Editor flaw, it executes code without user interaction.

This operation is supported by HorusProtector—a commercial-grade malware distribution and obfuscation platform that has steadily advanced since first emerging in 2024.

Embedded Payloads Mark New Era of HorusProtector Delivery

In contrast to earlier iterations that fetched malware from remote command-and-control (C2) servers, the latest HorusProtector build embeds the entire malicious payload directly within the VBE script—ballooning its size from a modest 10KB to a hefty 1.34MB.

Leveraging Visual Basic Scripts as a delivery mechanism, HorusProtector enables stealthy malware deployment without immediate reliance on external servers.

Once executed, the script uses PowerShell to inject the FormBook payload directly into system memory. This “living-off-the-land” technique allows the malware to masquerade as a legitimate process, significantly reducing the likelihood of detection.

XLoader: A Cross-Platform Data Theft Powerhouse

The campaign culminates in the deployment of XLoader, an advanced infostealer with roots in the notorious FormBook malware lineage.

Marketed as a Malware-as-a-Service (MaaS) offering on cybercrime forums, XLoader poses a threat to both Windows and macOS users—broadening its reach across platforms.

Once active, XLoader carries out a wide range of data theft operations, including:

  • Logging keystrokes and capturing screen activity
  • Snatching clipboard contents, including cryptocurrency transaction data
  • Extracting saved login credentials from browsers, email clients, and messaging apps
  • Scanning for and exfiltrating cryptocurrency wallet files
  • Delivering and executing secondary malware payloads on infected systems

Legacy Flaws, Modern Threats: Malware Still Thriving on Unpatched Systems

Although Microsoft patched the Equation Editor vulnerability back in 2017, it remains a popular target—largely due to inconsistent patching practices within organizations. This ongoing risk demonstrates how cybercriminals exploit known weaknesses when defenses lag behind.

To reduce exposure, security professionals strongly advise:

  • Keeping all Microsoft Office applications fully updated
  • Using advanced email filtering to block malicious file attachments
  • Disabling the Equation Editor feature if it’s not essential
  • Educating employees to recognize and avoid suspicious email content

“Continued distribution of malware exploiting legacy bugs signals that vulnerable environments are still widespread,” ASEC researchers cautioned.

This campaign is yet another reminder: outdated software isn’t just obsolete—it’s dangerous. Staying current on patches remains one of the most effective defenses against today’s evolving cyber threats.

More Articles & Posts