How To: Empire’s Cross Platform Office Macro
ID: 0204a582-648e-5496-a730-fd3d7f0e9d1f
STIX ID: report--0204a582-648e-5496-a730-fd3d7f0e9d1f
Feed Name: Black Hills Infosec Blog
This article describes a proof-of-concept technique for creating a single macro-enabled Office document that can compromise both Windows and macOS hosts by detecting the OS at runtime and launching the appropriate stager (PowerShell for Windows, Python/EmPyre for macOS). It provides step-by-step guidance for generating stagers with PowerShell Empire/EmPyre, embedding them in Office macros, and testing execution, noting limitations on older Mac Office builds and environments that restrict access to required libraries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
