Add-ins

T1137.006

Sub-technique of T1137 Office Application Startup.View on attack.mitre.org

About this technique

Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins.

Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.

Detection rules4

Rules on DetectionCode tagged with T1137.006.

Sigma4

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples4

Groups1

Used byProcedure example
GroupNaikon

Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.

Software3

Used byProcedure example
MalwareBisonal

Bisonal has been loaded through a `.wll` extension added to the ` %APPDATA%\microsoft\word\startup\` repository.

MalwareLunarLoader

LunarLoader has the ability to use Microsoft Outlook add-ins to establish persistence.

MalwareLunarMail

LunarMail has the ability to use Outlook add-ins for persistence.

References3

  1. FireEye Mail CDS 2018 Open source
    Caban, D. and Hirani, M. (2018, October 3). You’ve Got Mail! Enterprise Email Compromise. Retrieved November 17, 2024.
  2. MRWLabs Office Persistence Add-ins Open source
    Knowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.
  3. Microsoft Office Add-ins Open source
    Microsoft. (n.d.). Add or remove add-ins. Retrieved July 3, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.