Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool
Unknown threat actors have been seen distributing a surveillance tool named MerkSpy as part of a campaign that mainly targets users in Canada, India, Poland, and the United States by taking advantage of a security vulnerability in Microsoft MSHTML that has since been patched.
As stated by Cara Lin, a researcher at Fortinet FortiGuard Labs, in a paper released last week, MerkSpy is intended to surreptitiously record user activity, obtain sensitive data, and create persistence on infiltrated devices.
A Microsoft Word document purporting to be a software engineer job description serves as the initial point of attack for the chain.
However, accessing the file starts the exploitation of a high-severity MSHTML vulnerability called CVE-2021-40444, which could lead to remote code executi...

