Specula - Turning Outlook Into a C2 With One Registry Change
ID: 0c4aa8ad-eab9-5ed2-b6da-b06f113b4d63
STIX ID: report--0c4aa8ad-eab9-5ed2-b6da-b06f113b4d63
Feed Name: TrustedSec blog
TrustedSec publicly released 'Specula', a framework that weaponizes Outlook's home page/WebView by setting non-privileged HKCU Registry values to load attacker-controlled HTML which executes VBScript/jscript via Outlook's COM interfaces, enabling persistent beaconing C2 from the trusted outlook.exe process; the report details how the technique works, the framework's module/tasking model, lists specific Registry keys to monitor as IOCs, and provides mitigations (use New Outlook, GPO lockdown, disable VBScript, apply security baselines) and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
