Office Application Startup

T1137

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins.

A variety of features have been discovered in Outlook that can be abused to obtain persistence, such as Outlook rules, forms, and Home Page. These persistence mechanisms can work within Outlook or be used through Office 365.

Detection rules18

Rules on DetectionCode tagged with T1137 or one of its sub-techniques.

Sigma15

Splunk3

RuleTypeRiskData sourceTechnique
Windows Outlook LoadMacroProviderOnBoot PersistenceTTPNULLSysmon EventID 13T1137
Windows Outlook Macro Created by Suspicious ProcessTTPNULLSysmon EventID 11T1137
Windows Outlook Macro Security ModifiedTTPNULLSysmon EventID 13T1137

Sub-techniques6

IDNameExamples
T1137.001Office Template Macros5
T1137.002Office Test1
T1137.003Outlook Forms1
T1137.004Outlook Home Page2
T1137.005Outlook Rules1
T1137.006Add-ins4

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

Groups2

Used byProcedure example
GroupAPT32

APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence.

GroupGamaredon Group

Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the /altvba option, once the Application.Startup event is received.

References2

  1. SensePost Ruler GitHub Open source
    SensePost. (2016, August 18). Ruler: A tool to abuse Exchange services. Retrieved February 4, 2019.
  2. TechNet O365 Outlook Rules Open source
    Koeller, B.. (2018, February 21). Defending Against Rules and Forms Injection. Retrieved November 5, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.