Sub-technique of T1137 Office Application Startup.View on attack.mitre.org
Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins.
Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.
Rules on DetectionCode tagged with T1137.006.
| Rule | Level | Log source |
|---|---|---|
| Code Executed Via Office Add-in XLL File | high | windows / ps_script |
| Potential Persistence Via Excel Add-in - Registry | high | windows / registry_set |
| Potential Persistence Via Microsoft Office Add-In | high | windows / file_event |
| Potential Persistence Via Visual Studio Tools for Office | medium | windows / registry_set |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupNaikon | Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host. |
| Used by | Procedure example |
|---|---|
| MalwareBisonal | Bisonal has been loaded through a `.wll` extension added to the ` %APPDATA%\microsoft\word\startup\` repository. |
| MalwareLunarLoader | LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence. |
| MalwareLunarMail | LunarMail has the ability to use Outlook add-ins for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.