Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and functionality in Outlook messages. Custom Outlook forms can be created that will execute code when a specifically crafted email is sent by an adversary utilizing the same custom Outlook form.(Citation: SensePost Outlook Forms) Once malicious forms have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious forms will execute when an adversary sends a specifically crafted email to the user.(Citation: SensePost Outlook Forms)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Update Software
is blocked by Behavior Prevention on Endpoint
is blocked by Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
is blocked by Secure Baseline Configurations
is blocked by Phishing & Spam Protection
is blocked by Mobile Code
is blocked by Least Privilege
is blocked by Detonation Chambers (Sandboxes)
is blocked by Software & Firmware Patching
Impressum German English