Earlier this year, we observed an uptick in the number of attacks against Uyghur and Tibetan supporters using an updated version of the NetTraveler backdoor. The e-mail has two attachments, a non-malicious JPG file and a 373 KB Microsoft Word.DOC file. It contains an exploit for the CVE-2012-0158 vulnerability, detected by Kaspersky Lab products as ExploitMSWord.db. The main C&C module is dumped into %SystemRoot%system32sWindowsupdataney.dll, (detected as Trojan-Spy.Win32.TravNet.qfr)”]
Source: https://securelist.com/nettraveler-apt-gets-a-makeover-for-10th-birthday/66272/