A large email campaign used malicious Microsoft Word RTF attachments to exploit CVE-2017-0199 and install the Dridex banking trojan on vulnerable systems. Researchers said the operation targeted millions of recipients across numerous organizations, primarily in Australia, using lures such as "Scan Data" and spoofed sender formats to make booby-trapped documents appear legitimate. Proofpoint identified the activity as a notable shift for Dridex operators, who had more commonly relied on macro-enabled documents, while McAfee, FireEye, and Ars Technica reported that the exploit worked broadly across Windows versions of Word and could bypass common exploit mitigations.
The attack was especially dangerous because it did not require macros and could execute even when Word presented warning dialogs; in many Protected View cases, users only needed to click Enable Editing for the infection chain to proceed. Successful exploitation reportedly installed Dridex botnet ID 7500, and Microsoft issued a patch for the flaw on April 11 after researchers warned that the zero-day had already been rapidly weaponized in the wild. Separately, Microsoft has also disclosed CVE-2026-35440, an Important Microsoft Word information disclosure flaw that requires user interaction and is assessed as less likely to be exploited, but it was not reported as publicly exploited.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published advisory details for CVE-2026-35440, an Important Microsoft Word information disclosure vulnerability with a CVSS score of 5.5. The company said exploitation required user interaction, the Preview Pane was not an attack vector, the issue was not publicly disclosed or exploited, and a fix was available.
Microsoft released a security update for CVE-2017-0199 on April 11, 2017, after the flaw was weaponized in active Dridex spam campaigns. Researchers urged immediate patching because of the exploit's broad effectiveness across Word and Windows versions.
Proofpoint, along with other security firms including McAfee and FireEye, disclosed technical details of the campaign and said it marked the first Dridex activity they had observed using the newly disclosed Microsoft zero-day. They noted the exploit bypassed common mitigations, did not require macros, and could still succeed with minimal user interaction.
A large email campaign began using booby-trapped Word RTF documents exploiting CVE-2017-0199 to install the Dridex banking trojan. The campaign targeted millions of recipients across numerous organizations, primarily in Australia, and used lures such as "Scan Data."
Microsoft had reportedly known about the Microsoft Word remote-code-execution vulnerability later tracked as CVE-2017-0199 since January 2017, before public disclosure or a patch was issued.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcearstechnica.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.