Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareExploits 2 CVEs

W97M.DownLoader.2938

W97M.DownLoader.2938 is a family of downloader trojans identified by Dr.Web. It exploits vulnerabilities in Microsoft Office documents as an infection vector and is distributed via email-borne malicious documents/phishing documents. Its primary capability is to download additional malicious programs onto compromised computers. The malware was listed by Dr.Web among common email threats in Q4 2025 and Q1 2026. Related Office exploit activity mentioned alongside it includes Exploit.CVE-2017-11882.123 and Exploit.CVE-2018-0798.4, which target Microsoft Office vulnerabilities that allow arbitrary code execution. No specific threat actor, industry targeting, or standalone indicators of compromise were provided in the source content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2017-11882Microsoft Office Equation Editor Remote Code ExecutionExploited in the wild

W97M.DownLoader.2938 A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer. | Exploit.CVE-2017-11882.123 Exploit.CVE-2018-0798.4 Exploits designed to take advantage of Microsoft Office software vulnerabilities that allow an attacker to run arbitrary code.

via news drweb comnews.drweb.com
CVE-2018-0798Microsoft Office Equation Editor Memory Corruption RCEExploited in the wild

W97M.DownLoader.2938 A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer. | Exploit.CVE-2017-11882.123 Exploit.CVE-2018-0798.4 Exploits designed to take advantage of Microsoft Office software vulnerabilities that allow an attacker to run arbitrary code.

via news drweb comnews.drweb.com
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

Threat actors also used emails to distribute phishing documents and exploits.

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence1

W97M.DownLoader.2938 A family of downloader trojans that exploit vulnerabilities in Microsoft Office documents. They can also download other malicious programs to a compromised computer.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.