logo

Microsoft DDE protocol based malware attacks

ID: 81ade5d3-abe8-5a4c-b6bf-472c0c9d69e9

STIX ID: report--81ade5d3-abe8-5a4c-b6bf-472c0c9d69e9

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabz analysis describes active exploitation of Microsoft Word's DDE feature to deliver and execute malware (via PowerShell) across multiple campaigns: a PowerShell-Empire based post-exploitation chain, Locky ransomware distribution, and an APT28-linked campaign delivering Seduploader spyware. The report includes technical details (download URLs, IPs, RC4/AES/RSA behavior, registry persistence, scheduled tasks, cookie, and obfuscated scripts), observed TTPs, and mitigation advice (decline DDE prompts, registry disable, Microsoft advisory).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.