{"id":7857,"date":"2018-07-26T15:20:10","date_gmt":"2018-07-26T15:20:10","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/29168\/Old-Microsoft-Office-Flaws-Used-To-Create-Backdoors-Steal-Files.html"},"modified":"2018-07-26T15:20:10","modified_gmt":"2018-07-26T15:20:10","slug":"old-microsoft-office-flaws-used-to-create-backdoors-steal-files","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/","title":{"rendered":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2017\/10\/19\/d088989f-0fac-41ba-87b1-c9fb762546f6\/thumbnail\/770x578\/408bc20636a1586596373aafb2aa7530\/hacker-hands-and-code.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p><em>Video: Cyber threat intelligence vs business risk intelligence: Both are key to your firm&#8217;s security<\/em><\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">More security news<\/span><\/h3>\n<\/div>\n<p>A new hacking campaign aims to use old vulnerabilities in Microsoft Office software to create a backdoor into Windows systems in order to spy and steal files.<\/p>\n<p>Dubbed Felixroot, the malware is delivered to individuals in Ukraine using <a href=\"https:\/\/www.zdnet.com\/article\/what-is-phishing-how-to-protect-yourself-from-scam-emails-and-more\/\">a weaponised phishing email<\/a> claiming to contain seminar information on environmental protection, indicating that the selected victims are likely to be highly targeted. The message is written in Russian and claims to come from Kazakhstan.<\/p>\n<p>The Felixroot campaign has been unearthed by <a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2018\/07\/microsoft-office-vulnerabilities-used-to-distribute-felixroot-backdoor.html\" target=\"_blank\">researchers at FireEye<\/a>, who have linked it to a previous campaign using the same malware which targeted Ukrainians in September last year.<\/p>\n<p>This campaign exploits two Microsoft Office vulnerabilities: <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-0199\" target=\"_blank\">CVE-2017-0199<\/a> and <a href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2017-11882\" target=\"_blank\">CVE-2017-11882<\/a>.<\/p>\n<p>CVE-2017-0199 allows attackers to download and execute a Visual Basic script containing PowerShell commands when a user opens a document containing an embedded exploit, while CVE-2017-1882 allows attackers to run arbitrary code and potentially take control of a whole system.<\/p>\n<p>Both exploits came to light last year and have been used by malicious actors <a href=\"https:\/\/www.zdnet.com\/article\/password-stealing-eavesdropping-malware-targets-ukrainian-government\/\">in various campaigns<\/a>. In this new attack, the two exploits are being used to run Felixroot malware to create a backdoor in infected systems &#8212; and comes with all the processes needed to secretly monitor and exfiltate files.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>&#8220;Felixroot is looking to steal uploaded files from the targeted machine along with the system&#8217;s information. The architecture of the backdoor the includes features for Remote Shell, downloading, and executing files from the C2 server,&#8221; Swapnil Patil, researcher at FireEye, told ZDNet.<\/p>\n<p>In this case, the payload is delivered with a lure document &#8216;Seminar.rtf&#8217;, which exploits CVE-2017-0199 to download a second-stage payload onto the victim&#8217;s computer. This second-stage payload is equipped with CVE-2017-11882, enabling attackers to gain significant control over the system.<\/p>\n<p><strong>See also: <a href=\"https:\/\/www.zdnet.com\/article\/what-is-malware-everything-you-need-to-know-about-viruses-trojans-and-malicious-software\/\">What is malware? Everything you need to know about viruses, trojans and malicious software<\/a><\/strong><\/p>\n<p>This backdoor component comes with custom encryption and is loaded directly into memory without touching the disk, boosting its chances of remaining hidden as it carries out its tasks.<\/p>\n<p>Once successfully installed into the memory, the payload will sleep for 10 minutes before looking for the command to be launched and connecting with the C&amp;C server, which stolen data is secretly sent to.<\/p>\n<p>As part of the process, the malware also retrieves information about the infected system, including name, user name, volume serial number, Windows version, and processor architecture.<\/p>\n<p>Ultimately, Felixroot is designed to be a backdoor into the entire system and several commands reflect its intention to exfiltrate data. In an effort to avoid making its presence known, the malware sleeps for one minute following each task and before executing the next.<\/p>\n<p>Once Felixroot is done with its snooping, the malicious processes are terminated and all footprints on the targeted machine are removed. It&#8217;s a mode of operational security designed to ensure that even if the attack is discovered, it can&#8217;t be traced back to the group behind it.<\/p>\n<p>As the campaign is still under investigation, FireEye hasn&#8217;t revealed the specific targets of the attack or who the perpetrator might be. However, it&#8217;s believed the Felixroot is still active and could eventually expand the scope of its attacks.<\/p>\n<p><strong>See also:<\/strong> <strong><a href=\"https:\/\/www.techrepublic.com\/article\/can-russian-hackers-be-stopped-heres-why-it-might-take-20-years\/\" target=\"_blank\">Can Russian hackers be stopped? Here&#8217;s why it might take 20 years<\/a><\/strong><strong>[TechRepublic]<\/strong><\/p>\n<p>&#8220;All industries should be on alert, as it is highly likely that the threat actors will eventually move outside the scope of their current targeting. Also, in near future we can expect some more features included in the malware by threat actors,&#8221; said Patil.<\/p>\n<p>Felixroot takes advantage of vulnerabilities <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-fixes-exploited-critical-word-security-flaw\/\">which patches have long been available for<\/a>, so one of the best ways to avoid falling victm to this campaign is to ensure systems are updated and so protected against the exploits.<\/p>\n<p>However, this and <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-powerpoint-exploit-used-to-bypass-antivirus-and-spread-malware\/\">other campaigns<\/a> currently remain successful because plenty of organisations have failed to apply these updates.<\/p>\n<p>&#8220;Despite the release of patches, these vulnerabilities are targeted in the wild by threat actors because of the high percentage of success,&#8221; said Patil.<\/p>\n<h3>RELATED COVERAGE<\/h3>\n<p><a href=\"https:\/\/hub.zdnet.com\/content\/article\/75e23bad-b053-49ab-8fb2-a69cce2a64e0\/version\/us\" target=\"_blank\"><strong>Hacking campaign combines attacks to target government, finance, and energy<\/strong><\/a><\/p>\n<p>An attack group operating out of Iran is copying techniques used in successful high-profile attacks &#8212; but forget to cover their tracks, leaving their tactics exposed.<\/p>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/hacking-campaign-targets-iphone-users-with-data-stealing-location-tracking-malware\/\"><strong>Hacking campaign targets iPhone users with data-stealing, location-tracking malware<\/strong><\/a><\/p>\n<p>Campaign delivers fake versions of WhatsApp and Telegram to victims &#8211; and those behind it have tried to make it look like a Russian attack when it isn&#8217;t.<\/p>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/phishing-alert-hacking-gang-turns-to-new-tactics-in-malware-campaign\/\"><strong>Phishing alert: Hacking gang turns to new tactics in malware campaign<\/strong><\/a><\/p>\n<p>Security company warns &#8216;SilverTerrier&#8217; group poses a threat to businesses.<\/p>\n<p><a href=\"https:\/\/www.zdnet.com\/video\/securing-the-power-grid-from-hacking-sabotage-and-other-threats\/\"><strong>Securing the power grid from hacking, sabotage, and other threats<\/strong><\/a><\/p>\n<p>Frank Gaffney, founder and president of the Center for Security Policy, talks about securing the power grid from EMP, hacking, sabotage, and solar flares. He thinks transformers are the key element.<\/p>\n<p><strong>READ MORE ON CYBER CRIME<\/strong><\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/29168\/Old-Microsoft-Office-Flaws-Used-To-Create-Backdoors-Steal-Files.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":7858,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[2352],"class_list":["post-7857","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwaremicrosoftflawbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-07-26T15:20:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files\",\"datePublished\":\"2018-07-26T15:20:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/\"},\"wordCount\":848,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg\",\"keywords\":[\"headline,malware,microsoft,flaw,backdoor\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/\",\"name\":\"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg\",\"datePublished\":\"2018-07-26T15:20:10+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/07\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,microsoft,flaw,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwaremicrosoftflawbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/","og_locale":"en_US","og_type":"article","og_title":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-07-26T15:20:10+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files","datePublished":"2018-07-26T15:20:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/"},"wordCount":848,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg","keywords":["headline,malware,microsoft,flaw,backdoor"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/","url":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/","name":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg","datePublished":"2018-07-26T15:20:10+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/07\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files.jpg","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/old-microsoft-office-flaws-used-to-create-backdoors-steal-files\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,microsoft,flaw,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwaremicrosoftflawbackdoor\/"},{"@type":"ListItem","position":3,"name":"Old Microsoft Office Flaws Used To Create Backdoors, Steal Files"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/7857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=7857"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/7857\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/7858"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=7857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=7857"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=7857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}