Weaponize Your Word – Malicious Template Injection
ID: 4c9b0bd6-a2da-5a89-b57d-0bc83689d4c9
STIX ID: report--4c9b0bd6-a2da-5a89-b57d-0bc83689d4c9
Feed Name: JUMPSEC Labs
Threat Score
This report explains how attackers weaponize Microsoft Word remote templates by modifying a .docx to point at a remote macro-enabled .dotm, allowing otherwise benign documents to pull and execute VBA payloads (a technique observed being used by LockBit). It covers the technical steps to build the loader, obfuscation considerations, hosting approaches, and provides KQL-based detection queries and investigative guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
