logo

Specula - Turning Outlook Into a C2 With One Registry Change

ID: 0c4aa8ad-eab9-5ed2-b6da-b06f113b4d63

STIX ID: report--0c4aa8ad-eab9-5ed2-b6da-b06f113b4d63

Feed Name: TrustedSec blog

Threat Score
72/100

Date Published: 2024-07-29

Date Updated: 2026-05-01

...
...

TrustedSec publicly released 'Specula', a framework that weaponizes Outlook's home page/WebView by setting non-privileged HKCU Registry values to load attacker-controlled HTML which executes VBScript/jscript via Outlook's COM interfaces, enabling persistent beaconing C2 from the trusted outlook.exe process; the report details how the technique works, the framework's module/tasking model, lists specific Registry keys to monitor as IOCs, and provides mitigations (use New Outlook, GPO lockdown, disable VBScript, apply security baselines) and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.