FORENSIA

ATT&CK · T1137.006 · sub-technique

Add-ins

Tactics: persistence

About

Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.

Platforms: Windows, Office SuiteParent: T1137 Office Application StartupMITRE ATT&CK ↗

Used by actors

1 known groups

Software

3 malware/tools implement this

BisonalLunarMailLunarLoader

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1137.006.

No corpus indicators are tagged with this technique yet.