A new malware named CHAINSHOT was recently used to target Adobe Flash zero-day vulnerability (CVE-2018-5002). The malware was transferred using a Microsoft Excel file containing a tiny Shockwave Flash ActiveX object and the property called “Movie” containing a URL to download the flash application.
Read full news article on MSPoweruser