Microsoft DDE protocol based malware attacks
ID: 81ade5d3-abe8-5a4c-b6bf-472c0c9d69e9
STIX ID: report--81ade5d3-abe8-5a4c-b6bf-472c0c9d69e9
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabz analysis describes active exploitation of Microsoft Word's DDE feature to deliver and execute malware (via PowerShell) across multiple campaigns: a PowerShell-Empire based post-exploitation chain, Locky ransomware distribution, and an APT28-linked campaign delivering Seduploader spyware. The report includes technical details (download URLs, IPs, RC4/AES/RSA behavior, registry persistence, scheduled tasks, cookie, and obfuscated scripts), observed TTPs, and mitigation advice (decline DDE prompts, registry disable, Microsoft advisory).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
