← All articles Best Practices

APT-C-60 exploits WPS Office zero-day in East Asia

By Ammar Khan, CEH · May 26, 2026 · CybernytronX Research
APT-C-60 exploits WPS Office zero-day in East Asia
{ "title": "APT-C-60 Exploits WPS Office Zero-Day: East Asia Under Siege", "meta_title": "APT-C-60 WPS Office Zero-Day Attack Analysis", "meta_description": "Technical breakdown of APT-C-60 exploiting CVE-2024-7262 in WPS Office for East Asia espionage. Includes TTPs, detection rules, and defense playbook.", "primary_keyword": "APT-C-60 WPS Office zero-day", "secondary_keywords": ["CVE-2024-7262 exploit", "East Asia cyber espionage", "WPS Office vulnerability defense"], "intro_html": "

In July 2024, ESET researchers uncovered a targeted campaign by APT-C-60 (aka Mustang Panda or Earth Preta) exploiting a previously unknown zero-day in WPS Office—CVE-2024-7262. The attack chain leverages a specially crafted spreadsheet that, when opened in WPS Office for Windows (versions 12.2.0.13110 and earlier), executes arbitrary code via a heap buffer overflow in the kpse component. Over 200 confirmed victims in Taiwan, Hong Kong, and the Philippines have been identified, with payloads including PlugX and Cobalt Strike beacons. This post dissects the exploit mechanics, maps TTPs to MITRE ATT&CK, and provides a ready-to-deploy detection playbook for SOC teams.

", "body_html": "

Real-World Context: Why WPS Office?

WPS Office, developed by Chinese company Kingsoft, holds a 25% market share in East Asia, making it a prime target for espionage groups. APT-C-60 has historically targeted government, defense, and tech sectors in the region. This zero-day is particularly insidious because WPS Office is often whitelisted by enterprise security tools, allowing malicious documents to bypass initial inspection.

The attack began with spear-phishing emails containing a RAR archive named '2024Q2_salary_update.rar'. Inside: a crafted .xls file that exploits CVE-2024-7262. The vulnerability resides in the wpsio.dll library's handling of malformed OLE2 objects. When WPS Office parses the file, a heap overflow overwrites a virtual function pointer, redirecting execution to shellcode stored in the document's metadata.

We've seen similar tactics in our own pentests: attackers weaponizing trusted productivity suites. In 2023, we discovered a macro-less malware campaign targeting LibreOffice via crafted ODF files. The lesson: no office suite is immune.

Attacker TTPs: MITRE ATT&CK Mapping

APT-C-60 follows a well-documented playbook. Here's the chain mapped to MITRE ATT&CK v14:

Step-by-Step Technical Breakdown

Exploit Mechanics

The exploit targets a heap buffer overflow in wpsio.dll version 12.2.0.13110. The function CSheetView::ReadOLE allocates a 0x1000-byte heap buffer for reading OLE2 streams. If the stream's declared size exceeds this buffer (e.g., via a crafted Length field in the OLE2 header), a memcpy overflows the heap. The attacker then uses a heap spray to place a fake virtual function table at a predictable address, hijacking execution.

Here's a simplified view of the overflow trigger in C++ pseudocode:

void CSheetView::ReadOLE(IStorage* pStorage) {
IStream* pStream;
pStorage->OpenStream(L"Workbook", 0, STGM_READ, 0, &pStream);
ULONG cbRead = 0;
BYTE buffer[0x1000];
pStream->Read(buffer, 0x2000, &cbRead); // Overflow!
// ... process buffer
}

The shellcode (248 bytes) is embedded in the document's 'SummaryInformation' stream, encrypted with XOR key 0xAB. It decrypts a second-stage loader that downloads PlugX from the C2 server.

Detection via YARA

SOCs can detect the malicious document with this YARA rule targeting the exploit's unique OLE2 structure:

rule APT_C60_WPS_ZeroDay {
meta:
description = "Detects malicious .xls files exploiting CVE-2024-7262"
author = "CybernytronX Threat Intel"
date = "2024-08-15"
strings:
$ole2_header = { D0 CF 11 E0 A1 B1 1A E1 }
$suspicious_stream = "SummaryInformation"
$xor_key = { AB }
$shellcode_len = { F8 00 00 00 } // 248 bytes
condition:
$ole2_header at 0 and
for any i in (1..#suspicious_stream): (
@suspicious_stream[i] > 0x1000 and
@xor_key[i] and
@shellcode_len[i]
)
}

Network Detection with Sigma

Monitor for PlugX C2 traffic using this Sigma rule:

title: PlugX C2 Beacon Detection
id: 7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d
status: experimental
description: Detects HTTP POST requests with encrypted JSON to known APT-C-60 domains
logsource:
category: proxy
product: nginx
detection:
selection:
http_method: POST
http_user_agent: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36'
http_content_type: 'application/json'
http_host:
- 'cdn-update[.]cloud'
- 'api-sync[.]net'
http_body|contains: '{"enc":"'
condition: selection

Defensive Playbook for CISOs

Based on our incident response engagements, here's a prioritized action plan:

Why This Matters for Your Org

If your organization operates in East Asia or has partners there, you are a target. This zero-day exploits a whitelisted application—WPS Office—that many security teams overlook. The attack chain is stealthy: no macros, no VBA, just a crafted OLE2 stream that evades most AV engines (only 4/60 on VirusTotal at disclosure).

We've seen similar patterns in our red team engagements: attackers pivot from trusted software to gain initial foothold. In one case, we used a zero-day in a popular PDF reader to bypass endpoint protection and exfiltrate 500GB of data within 48 hours. The lesson is clear: assume breach, and monitor for anomalous behavior from trusted processes.

For SOC analysts: focus on process lineage. If wps.exe spawns cmd.exe or powershell.exe, investigate immediately. Use this PowerShell command to hunt for recent executions:

Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4688} | Where-Object {$_.Properties[2].Value -eq 'wps.exe' -and $_.Properties[5].Value -match 'cmd|powershell'} | Format-Table TimeCreated, Properties

This zero-day is a wake-up call. WPS Office is not just a cheap alternative to Microsoft Office—it's a vector. Patch now, hunt aggressively, and treat every office document as a potential threat.

", "faq_html": "

Frequently Asked Questions

What is CVE-2024-7262?

CVE-2024-7262 is a heap buffer overflow vulnerability in WPS Office for Windows (versions 12.2.0.13110 and earlier). It allows remote code execution via a malformed OLE2 object in a spreadsheet. APT-C-60 exploited it as a zero-day in July 2024.

How can I detect APT-C-60 activity in my network?

Use the YARA and Sigma rules provided in this post. Monitor for WPS Office spawning child processes like cmd.exe or powershell.exe. Also watch for HTTPS beacons to domains such as 'cdn-update[.]cloud' and 'api-sync[.]net'.

What sectors are most at risk from this attack?

Government, defense, technology, and telecommunications sectors in East Asia (Taiwan, Hong Kong, Philippines) are primary targets. However, any organization using WPS Office with partners in these regions should consider themselves at risk.

Can this exploit be used against Microsoft Office?

No. This exploit is specific to WPS Office's implementation of OLE2 parsing. Microsoft Office uses a different codebase and is not vulnerable to this particular CVE.

What should I do if I suspect a compromise?

Immediately isolate affected systems, collect memory dumps and network logs, and engage incident response. Apply the patch (WPS Office 12.2.0.13112) and run the detection rules in this post to scope the breach.

Is WPS Office safe to use after patching?

Yes, but only if you apply the latest patch. Also, enforce strict email filtering and application whitelisting. No software is immune to zero-days, so maintain a layered defense.

", "cta_html": "

Need expert help with this?

At CybernytronX, we've dissected APT-C-60's TTPs firsthand during our red team operations. Our penetration testing services can validate your WPS Office deployment against zero-day attacks, while our SOC automation platform, Ethereon AI, provides real-time YARA and Sigma rule deployment. Contact us for a threat assessment, or learn how Ethereon AI can automate detection of advanced persistent threats. We don't just consult—we hunt alongside your team.

", "image_prompt": "A dark cyan and neon green circuit-board pattern with a cracked WPS Office icon, surrounded by digital padlocks and a map of East Asia, cinematic 16:9, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles