Template Injection

T1221

Technique.View on attack.mitre.org

About this technique

Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft’s Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered.

Properties within parts may reference shared public resources accessed via online URLs. For example, template properties may reference a file, serving as a pre-formatted document blueprint, that is fetched when the document is loaded.

Adversaries may abuse these templates to initially conceal malicious code to be executed via user documents. Template references injected into a document may enable malicious payloads to be fetched and executed when the document is loaded. These documents can be delivered via other techniques such as Phishing and/or Taint Shared Content and may evade static detections since no typical indicators (VBA macro, script, etc.) are present until after the malicious payload is fetched. Examples have been seen in the wild where template injection was used to load malicious code containing an exploit.

Adversaries may also modify the *\template control word within an .rtf file to similarly conceal then download malicious code. This legitimate control word value is intended to be a file destination of a template file resource that is retrieved and loaded when an .rtf file is opened. However, adversaries may alter the bytes of an existing .rtf file to insert a template control word field to include a URL resource of a malicious payload.

This technique may also enable Forced Authentication by injecting a SMB/HTTPS (or other credential prompting) URL and triggering an authentication attempt.

Detection rules1

Rules on DetectionCode tagged with T1221.

Sigma1

RuleLevelLog source
Server Side Template Injection StringshighNULL / webserver

Splunk0

No Splunk rules are mapped to this technique yet.

Groups8

Software2

Campaigns2

Procedure examples12

Groups8

Used byProcedure example
GroupAPT28

APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro.

GroupConfucius

Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit.

GroupDarkHydrus

DarkHydrus used an open-source tool, Phishery, to inject malicious remote template URLs into Microsoft Word documents and then sent them to victims to enable Forced Authentication.

GroupDragonfly

Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication.

GroupGamaredon Group

Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems.

GroupInception

Inception has used decoy documents to load malicious remote payloads via HTTP.

GroupMirrorFace

MirrorFace has used remote template injection to retrieve malicious payloads from the C2.

GroupTropic Trooper

Tropic Trooper delivered malicious documents with the XLSX extension, typically used by OpenXML documents, but the file itself was actually an OLE (XLS) document.

Software2

Used byProcedure example
MalwareChaes

Chaes changed the template target of the settings.xml file embedded in the Word document and populated that field with the downloaded URL of the next payload.

MalwareWarzoneRAT

WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document.

Campaigns2

Used byProcedure example
CampaignFrankenstein

During Frankenstein, the threat actors used trojanized documents that retrieved remote templates from an adversary-controlled website.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.

References9

  1. Anomali Template Injection MAR 2018 Open source
    Intel_Acquisition_Team. (2018, March 1). Credential Harvesting and Malicious File Delivery using Microsoft Office Template Injection. Retrieved July 20, 2018.
  2. Ciberseguridad Decoding malicious RTF files Open source
    Pedrero, R.. (2021, July). Decoding malicious RTF files. Retrieved November 16, 2021.
  3. MalwareBytes Template Injection OCT 2017 Open source
    Segura, J. (2017, October 13). Decoy Microsoft Word document delivers malware through a RAT. Retrieved July 21, 2018.
  4. Microsoft Open XML July 2017 Open source
    Microsoft. (2014, July 9). Introducing the Office (2007) Open XML File Formats. Retrieved July 20, 2018.
  5. Proofpoint RTF Injection Open source
    Raggi, M. (2021, December 1). Injection is the New Black: Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors . Retrieved December 9, 2021.
  6. Redxorblue Remote Template Injection Open source
    Hawkins, J. (2018, July 18). Executing Macros From a DOCX With Remote Template Injection. Retrieved October 12, 2018.
  7. SANS Brian Wiltse Template Injection Open source
    Wiltse, B.. (2018, November 7). Template Injection Attacks - Bypassing Security Controls by Living off the Land. Retrieved April 10, 2019.
  8. Talos Template Injection July 2017 Open source
    Baird, S. et al.. (2017, July 7). Attack on Critical Infrastructure Leverages Template Injection. Retrieved July 21, 2018.
  9. ryhanson phishery SEPT 2016 Open source
    Hanson, R. (2016, September 24). phishery. Retrieved July 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.