Skip to content
Threat Feed

Tag

Outlook

8 briefs RSS
medium advisory

PowerShell Local Email Collection Techniques

Adversaries use PowerShell scripts leveraging Outlook COM objects to programmatically access and exfiltrate user email data from local systems.

collection powershell outlook
1r 1t
medium advisory

Modification of Outlook Security Registry Settings

Detects unauthorized modifications to Microsoft Outlook security-related registry keys that may be used to weaken email protections or establish persistence.

persistence windows registry outlook
1t
high advisory

Outlook WebView Registry Modification for Persistence

Adversaries can achieve persistence and code execution by modifying the Outlook WebView registry keys to point to a malicious URL.

Outlook persistence registry windows
1r 1t
high advisory

Outlook Home Page Registry Modification for Command and Control or Persistence

Attackers abuse the Outlook Home Page functionality by modifying specific registry keys to point to attacker-controlled URLs or file paths, enabling command and control or persistence on compromised Windows systems.

Outlook registry command-and-control persistence windows
2r 2t
medium advisory

Persistence via Malicious Microsoft Outlook VBA Template

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.

Outlook persistence vba windows
2r 1t
medium advisory

Outlook Security Settings Registry Modification

Attackers modify Outlook security settings via registry changes to enable malicious mail rules and bypass security controls, potentially leading to persistence and data compromise.

Microsoft Outlook persistence registry_modification outlook email
2r 1t
high advisory

Outlook Dialogs Disabled by Unusual Process

The detection identifies the modification of the Windows Registry key 'PONT_STRING' under Outlook Options by a process other than Outlook.exe, potentially indicating malware activity such as NotDoor.

Outlook +3 registry_modification malware notdoor
2r 1t
medium advisory

Microsoft Outlook VBA Template Persistence

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file.

Outlook persistence vba windows
2r 1t