'PhantomBlu' Cyberattackers Backdoor Microsoft Office Users via OLE
ID: 12afac24-a161-594a-95ba-42fb8bb578cd
STIX ID: report--12afac24-a161-594a-95ba-42fb8bb578cd
Feed Name: Dark Reading
Date Published: 2024-03-19
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Perception Point researchers uncovered the 'PhantomBlu' phishing campaign targeting US organizations where attackers send password-protected .docx attachments that prompt users to enable editing and click an embedded OLE 'printer' object; the OLE template manipulation and template injection deliver NetSupport RAT (a legitimate remote-support tool abused for espionage), and the report includes TTPs, IOCs, observed infrastructure (including use of Brevo), and recommended user and admin mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
