216.73.217.22

A Closer Look at Outlook Macros and More

· Published 15/11/2025 04:44 · Modified 17/11/2025 09:53

Export JSON

Essential information

Published
15/11/2025 04:44
Modified
17/11/2025 09:53
Tags
2025-11-15 backdoor c2 dll sideloading notdoor outlook macros persistence powershell registry modification
Related entities
1 intrusion sets (apt), 2 techniques (mitre), 1 malware

Description

The analysis examines , a utilizing for and lateral movement. It stages files in C:\ProgramData, employing with OneDrive.exe. The malware creates directories, executes encoded commands, and modifies registry entries to enable macros and disable security dialogs. Key tactics include using Outlook functions for communication and email monitoring. The blog provides detection strategies, including monitoring for suspicious commands, registry modifications, and creation of VbaProject.OTM files by non-Outlook processes. Splunk-based detection rules are offered to identify these malicious activities.

External references