New Specula tool uses Outlook for remote code execution in Windows
ID: fe45f022-a78e-56d8-a6bb-241107f3467b
STIX ID: report--fe45f022-a78e-56d8-a6bb-241107f3467b
Feed Name: Bleeping Computer
TrustedSec released Specula, a red-team C2 framework that converts Microsoft Outlook into a command-and-control beacon by setting custom Outlook Home Pages via WebView registry keys (abusing CVE-2017-11774 pathways and registry entries) to serve VBScript/JS that executes arbitrary commands; while the CVE was patched in 2017, the registry-based approach can persist on modern Office builds and has been used historically by APT actors, posing a practical persistence and lateral-movement risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
