Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Case Study: Credit Union Boosts Threat Prevention & Detection with Cymulate
Learn More
New Research: Cymulate Research Labs Discovers Token Validation Flaw
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

APT37 Exploits Microsoft Internet Explorer Zero Day Vulnerability

December 11, 2022

The APT37 threat group was discovered exploiting a remote code execution vulnerability in Windows Scripting Languages (CVE-2022-41128). The initial infection vector consisted of malicious Microsoft Office documents along with a rich text file (RTF) remote template. Successful exploitation requires the victim to disable protected view before the remote RTF template is downloaded.