Phishing with PowerPoint
ID: a6bbe152-9545-5c49-9236-407982104d97
STIX ID: report--a6bbe152-9545-5c49-9236-407982104d97
Feed Name: Black Hills Infosec Blog
Threat Score
This blog post from Black Hills InfoSec demonstrates a method to force PowerPoint to execute embedded VBA macros immediately upon opening by adding a customUI.xml with an onLoad callback and repackaging the .pptm; it includes step‑by‑step instructions, sample macro code, and a note that the technique may be outdated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
