Dynamic Data Exchange

T1559.002

Sub-technique of T1559 Inter-Process Communication.View on attack.mitre.org

About this technique

Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous inter-process communication (IPC) between applications. Once a link is established, applications can autonomously exchange transactions consisting of strings, warm data links (notifications when a data item changes), hot data links (duplications of changes to a data item), and requests for command execution.

Object Linking and Embedding (OLE), or the ability to link data between documents, was originally implemented through DDE. Despite being superseded by Component Object Model, DDE may be enabled in Windows 10 and most of Microsoft Office 2016 via Registry keys.

Microsoft Office documents can be poisoned with DDE commands, directly or through embedded files, and used to deliver execution via Phishing campaigns or hosted Web content, avoiding the use of Visual Basic for Applications (VBA) macros. Similarly, adversaries may infect payloads to execute applications and/or commands on a victim device by way of embedding DDE formulas within a CSV file intended to be opened through a Windows spreadsheet program.

DDE could also be leveraged by an adversary operating on a compromised machine who does not have direct access to a Command and Scripting Interpreter. DDE execution can be invoked remotely via Remote Services such as Distributed Component Object Model (DCOM).

Detection rules1

Rules on DetectionCode tagged with T1559.002.

Sigma1

RuleLevelLog source
Enable Microsoft Dynamic Data Exchangemediumwindows / registry_set

Splunk0

No Splunk rules are mapped to this technique yet.

Groups11

Software8

Campaigns1

Procedure examples20

Groups11

Used byProcedure example
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

GroupAPT37

APT37 has used Windows DDE for execution of commands and a malicious VBS.

GroupBITTER

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

GroupFIN7

FIN7 spear phishing campaigns have included malicious Word documents with DDE execution.

GroupGallmaker

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

View all 11 groups examples

Software8

Used byProcedure example
MalwareGravityRAT

GravityRAT has been delivered via Word documents using DDE for execution.

MalwareHAWKBALL

HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode.

MalwareKeyBoy

KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads.

MalwarePoetRAT

PoetRAT was delivered with documents using DDE to execute malicious code.

MalwarePOWERSTATS

POWERSTATS can use DDE to execute additional payloads on compromised hosts.

MalwareRamsay

Ramsay has been delivered using OLE objects in malicious documents.

MalwareRTM

RTM can search for specific strings within browser tabs using a Dynamic Data Exchange mechanism.

MalwareValak

Valak can execute tasks via OLE.

Campaigns1

Used byProcedure example
CampaignOperation Sharpshooter

During Operation Sharpshooter, threat actors sent malicious Word OLE documents to victims.

References10

  1. BleepingComputer DDE Disabled in Word Dec 2017 Open source
    Cimpanu, C. (2017, December 15). Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks. Retrieved December 19, 2017.
  2. CSV Excel Macro Injection Open source
    Ishaq Mohammed . (2021, January 10). Everything about CSV Injection and CSV Excel Macro Injection. Retrieved February 7, 2022.
  3. Enigma Reviving DDE Jan 2018 Open source
    Nelson, M. (2018, January 29). Reviving DDE: Using OneNote and Excel for Code Execution. Retrieved February 3, 2018.
  4. Fireeye Hunting COM June 2019 Open source
    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.
  5. Kettle CSV DDE Aug 2014 Open source
    Kettle, J. (2014, August 29). Comma Separated Vulnerabilities. Retrieved November 22, 2017.
  6. Microsoft ADV170021 Dec 2017 Open source
    Microsoft. (2017, December 12). ADV170021 - Microsoft Office Defense in Depth Update. Retrieved February 3, 2018.
  7. Microsoft DDE Advisory Nov 2017 Open source
    Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017.
  8. OWASP CSV Injection Open source
    Albinowax Timo Goosen. (n.d.). CSV Injection. Retrieved February 7, 2022.
  9. SensePost MacroLess DDE Oct 2017 Open source
    Stalmans, E., El-Sherei, S. (2017, October 9). Macro-less Code Exec in MSWord. Retrieved November 21, 2017.
  10. SensePost PS DDE May 2016 Open source
    El-Sherei, S. (2016, May 20). PowerShell, C-Sharp and DDE The Power Within. Retrieved November 22, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.