logo

How to Get Malicious Macros Past Email Filters

ID: 292d995e-24ec-5158-86bd-7694f0cbcef2

STIX ID: report--292d995e-24ec-5158-86bd-7694f0cbcef2

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-06-05

Date Updated: 2026-04-27

Author: BHIS

...
...

This advisory demonstrates practical techniques for weaponizing Microsoft Office macros to bypass email filters and sandboxes—covering legacy .doc formatting, invoking Shell.Application to fetch and open remote HTA payloads via WebDAV, generating HTA payloads (e.g., with PowerShell Empire), and writing payloads to target-specific file paths to evade sandbox environments; it warns defenders about the risk of allowing externally sourced macro-enabled documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.