Analysis of CVE-2018-8174 VBScript 0day and APT actor related to Office targeted attack – 奇虎360技术博客
ID: 421ef76c-e757-43ac-b94e-5dc17f389a02
STIX ID: report--421ef76c-e757-43ac-b94e-5dc17f389a02
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-05-10
Last Modified Date: 2018-05-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
360 Helios Team describes discovery and analysis of an in-the-wild Office/IE attack chain that leveraged the VBScript zero-day CVE-2018-8174 ("double kill") to achieve remote code execution, deliver PowerShell and reflective-PE payloads, and deploy Retro-series backdoors with UAC bypass and DLL hijacking; the report provides technical exploitation details (UAF/type confusion, fake SAFEARRAY, CONTEXT/VirtualProtect DEP bypass), payload behavior, attribution to APT-C-06, timeline, and appended IOCs.
