logo

Phishing with PowerPoint

ID: a6bbe152-9545-5c49-9236-407982104d97

STIX ID: report--a6bbe152-9545-5c49-9236-407982104d97

Feed Name: Black Hills Infosec Blog

Threat Score
50/100

Date Published: 2016-05-16

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post from Black Hills InfoSec demonstrates a method to force PowerPoint to execute embedded VBA macros immediately upon opening by adding a customUI.xml with an onLoad callback and repackaging the .pptm; it includes step‑by‑step instructions, sample macro code, and a note that the technique may be outdated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.