How to Get Malicious Macros Past Email Filters
ID: 292d995e-24ec-5158-86bd-7694f0cbcef2
STIX ID: report--292d995e-24ec-5158-86bd-7694f0cbcef2
Feed Name: Black Hills Infosec Blog
Threat Score
This advisory demonstrates practical techniques for weaponizing Microsoft Office macros to bypass email filters and sandboxes—covering legacy .doc formatting, invoking Shell.Application to fetch and open remote HTA payloads via WebDAV, generating HTA payloads (e.g., with PowerShell Empire), and writing payloads to target-specific file paths to evade sandbox environments; it warns defenders about the risk of allowing externally sourced macro-enabled documents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
