logo

'PhantomBlu' Cyberattackers Backdoor Microsoft Office Users via OLE

ID: 12afac24-a161-594a-95ba-42fb8bb578cd

STIX ID: report--12afac24-a161-594a-95ba-42fb8bb578cd

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-03-19

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Perception Point researchers uncovered the 'PhantomBlu' phishing campaign targeting US organizations where attackers send password-protected .docx attachments that prompt users to enable editing and click an embedded OLE 'printer' object; the OLE template manipulation and template injection deliver NetSupport RAT (a legitimate remote-support tool abused for espionage), and the report includes TTPs, IOCs, observed infrastructure (including use of Brevo), and recommended user and admin mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.