Security researchers from Security Qihoo 360 Core revealed that they uncovered an IE 0day vulnerability has been embedded in malicious MS Office document, targeting limited users by a known APT actor. An office document abused by cyber criminals and distributed this Zero-day vulnerability called double kill to exploit latest versions of Internet Explorer and applications that use the IE kernel. The late exploit phase of the attack uses public UAC bypass techniques and uses file steganography and memory reflection loading to avoid traffic monitoring and fileless downloads.”]