logo

New Specula tool uses Outlook for remote code execution in Windows

ID: fe45f022-a78e-56d8-a6bb-241107f3467b

STIX ID: report--fe45f022-a78e-56d8-a6bb-241107f3467b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-29

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

TrustedSec released Specula, a red-team C2 framework that converts Microsoft Outlook into a command-and-control beacon by setting custom Outlook Home Pages via WebView registry keys (abusing CVE-2017-11774 pathways and registry entries) to serve VBScript/JS that executes arbitrary commands; while the CVE was patched in 2017, the registry-based approach can persist on modern Office builds and has been used historically by APT actors, posing a practical persistence and lateral-movement risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.