logo

Weaponize Your Word – Malicious Template Injection

ID: 4c9b0bd6-a2da-5a89-b57d-0bc83689d4c9

STIX ID: report--4c9b0bd6-a2da-5a89-b57d-0bc83689d4c9

Feed Name: JUMPSEC Labs

Threat Score
70/100

Date Published: 2024-10-30

Date Updated: 2026-04-28

Author: Max Clarke

...
...

This report explains how attackers weaponize Microsoft Word remote templates by modifying a .docx to point at a remote macro-enabled .dotm, allowing otherwise benign documents to pull and execute VBA payloads (a technique observed being used by LockBit). It covers the technical steps to build the loader, obfuscation considerations, hosting approaches, and provides KQL-based detection queries and investigative guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.