logo

Threats That Hide in Your Microsoft Office Documents

ID: bb582547-cba2-5528-b7b8-46944125639f

STIX ID: report--bb582547-cba2-5528-b7b8-46944125639f

Feed Name: Cofense Blog

Threat Score
72/100

Date Published: 2024-05-29

Date Updated: 2026-04-27

Author: Hillary Long

...
...

This report outlines the abuse of Microsoft Office documents as a distribution vector for credential phishing and malware, covering embedded links, QR codes, VBA macros, and exploitation of CVE-2017-11882 and CVE-2017-0199. It details observed campaigns (Emotet, DarkGate) and payloads (FormBook, Agent Tesla), demonstrates typical infection chains (HTA in RTF, equation-editor buffer overflow, PowerShell IEX), and highlights the role of open-source tools in easing malicious document creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.