Malicious PowerPoint Documents on the Rise
ID: 7f9828ff-0c77-544b-af9c-ac7bf31670e7
STIX ID: report--7f9828ff-0c77-544b-af9c-ac7bf31670e7
Feed Name: McAfee Labs Blog
Threat Score
McAfee Labs observed a phishing campaign delivering AgentTesla via malicious PowerPoint .ppam add-ins: when opened the add-in auto-runs VBA that launches mshta and PowerShell to download and execute encoded payloads (agent DLL/EXE), injects via MSBuild, and establishes persistence by creating a scheduled task; the report includes URLs, file and EML hashes as IOCs and provides detection/mitigation guidance including an expert rule and AMSI/DAT coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
