Zero Day Exploitation Microsoft Follina by Athenian Tech

Zero Day Exploitation

The MSDT “Follina” zero‑day (CVE‑2022‑30190) emerged as a high‑severity exploitation vector in which attackers weaponised Microsoft Office documents to execute code via the Microsoft Support Diagnostic Tool. The vulnerability enabled remote code execution without macros, triggering when a user opened—or even previewed—a malicious file.

The MSDT “Follina” zero‑day (CVE‑2022‑30190) emerged as a high‑severity exploitation vector in which attackers weaponised Microsoft Office documents to execute code via the Microsoft Support Diagnostic Tool. The vulnerability enabled remote code execution without macros, triggering when a user opened—or even previewed—a malicious file.

Threat campaigns leveraged invoice‑themed lures, tender documents, HR files, and government‑style templates to compromise government agencies, enterprises, and high‑value targets. Once activated, the exploit delivered C2 beacons, credential‑harvesting payloads, and loaders that established persistent footholds within corporate environments.

Athenian Tech’s Role

Athenian Tech’s Prime intelligence platform played a central role in detecting and containing live exploitation attempts. The platform did the following:

  • Identified concentrated clusters of malicious Office documents and exploit‑linked URLs across email, web, and endpoint telemetry.
  • Correlated hashes, domains, URLs, and C2 infrastructure with Dark Web exploit‑kit sellers and underground operator chatter.
  • Issued rapid‑response advisories recommending MSDT handler disablement, EDR detections, IOC blocks, and emergency patching across client environments.

Impact

Athenian Tech’s intervention led to:

  • Disrupted active Follina attack chains before lateral movement or credential compromise could escalate.
  • Significantly reduced MTTD and MTTR for affected organisations during the zero‑day window.
  • Assisted enterprises in updating hardening baselines and response playbooks to address future Office handler–based zero‑day vulnerabilities.
Share

Related Case Studies

Deepfake of Narayan Murthy SurfacesDeepfake
CASE STUDY01 August 2025

Deepfake of Narayan Murthy Surfaces

In August 2025 a coordinated financial fraud campaign which leveraged AI-generated deepfake technology to impersonate Infosys Founder Narayana Murthy, falsely portraying him as endorsing a fictitious government-backed investment platform surfaced across social media platforms. The manipulated video circulated across Facebook, Instagram, and WhatsApp, claimed that citizens could earn over ₹1.9 lakh per month by making a one time investment of ₹ 21,000 through an “AI-powered automated smart investing” scheme.

Read Case Study →
BSNLTelecom
CASE STUDY20 May 2024

Breach at Telecom Major BSNL

On 20 May 2024, government owned telecom major BSNL and a critical part of India’s national communications infrastructure, was hit by a major cybersecurity incident. The same day, a threat actor—kiberphant0m—claimed responsibility of the attack and advertised the sale of approximately 278 GB of sensitive telecom data on the dark web. The exposed data included IMSI numbers, SIM subscriber details, Home Location Register (HLR) records, and internal Solaris server snapshots, all of which are vital for telecom operations and subscriber identity management.

Read Case Study →
Breach in the Department of DefenceCybercrime
CASE STUDY

Breach in the Department of Defence

On 10 March 2025, Athenian Tech (AT) identified a significant security breach affecting a sensitive national defence division after the ransomware group Babuk Locker 2.0 claimed to have exfiltrated nearly 20TB of classified defence data. The leaked dataset reportedly included sensitive information like VVIP evacuation procedures.

Read Case Study →

Get the next one in your inbox.

The Month in Threats, Read by the People Who Have to Answer for It.

Free. Unsubscribe any time. We never sell or share your address.