Phishing campaign reportedly uses old Office flaw to deliver fileless XWorm

THE BRIEF
CSO Online reports that Fortinet researchers identified a phishing campaign delivering the commercially available XWorm malware through a chain that combines an older Microsoft Office vulnerability with fileless execution. The reported campaign uses multi-themed phishing emails and a malicious Excel add-in to exploit CVE-2018-0802, a memory corruption flaw that Microsoft patched in 2018. After that step, the campaign reportedly deploys a modular remote access trojan capable of encrypted command-and-control communications and plugin-based expansion. The source describes the approach as notable less for a new technique than for assembling familiar components into a single execution chain. The reporting does not establish the campaign’s scope or affected organizations. It does, however, highlight how a known Office weakness, a malicious spreadsheet add-in, and fileless behavior can appear together in one phishing operation. For defenders, the combination makes patching, attachment scrutiny, and monitoring of suspicious Office and endpoint activity relevant.
WHY IT MATTERS
This report matters because it illustrates that defenders may face risk from familiar weaknesses when they are combined with phishing and fileless execution. A known flaw’s age does not by itself remove its relevance when malicious Excel add-ins remain part of a reported delivery chain. XWorm’s encrypted command-and-control capability and plugin-based design, as described by the source, may complicate visibility and response. The case also reinforces the value of treating email, Office, and endpoint controls as connected defenses rather than isolated layers.
WHO SHOULD CARE
Microsoft Office administrators, email-security teams, endpoint defenders, vulnerability managers, and security leaders should review protections against malicious Excel add-ins, legacy Office vulnerabilities, and fileless malware behavior.
WHAT TO DO NOW
- Verify that Microsoft Office installations are patched against CVE-2018-0802 and other applicable security updates.
- Review whether Excel add-ins are restricted, approved, and monitored across managed environments.
- Strengthen phishing controls for multi-themed messages carrying spreadsheet attachments or add-ins.
- Use endpoint monitoring to investigate fileless execution, encrypted command-and-control activity, and unexpected plugin behavior associated with XWorm.