A recently discovered Microsoft Office document exploit builder kit dubbed ThreadKit has been used to spread a variety of malware, including banking Trojans and RATs. The exploit kit was first discovered in October 2017, but according to the experts, crooks are using it at least since June 2017. The ThreadKit builder kit shows similarities to Microsoft Word Intruder (MWI), it was initially being advertised in a forum post as a builder for weaponized decoy documents. The documents were triggering the CVE-2017-0199 vulnerability in Office to download an HTA file that would then download the decoy and a malicious VB script to extract and run the embedded executable.”]
Source: https://securityaffairs.co/wordpress/70719/hacking/threadkit-exploit-builder.html

