October 16, 2017 By Douglas Bonderud 2 min read

Macro-based Microsoft Office malware is a go-to tactic for aspiring cybercriminals because it’s reliable and effective. Since macros remain an integral part of Word documents, many companies don’t disable them by default, and users often open .doc attachments.

But with enterprise IT on the war path for signs of any macro malware attack, criminals are getting creative. According to Bleeping Computer, they’re now using an outdated Office feature known as Dynamic Data Exchange (DDE) to infiltrate and infect corporate devices.

Legacy’s Long Shadow

DDE allows Office applications to cross-load data from each other, which enables Word to quickly grab information from other Office apps. In practice, it’s just a custom field that lets users specify where data is pulled from and what type of data is injected. DDE has since been replaced by Microsoft’s Object Linking and Embedding (OLE) toolkit, but it’s still available on a per-application basis.

Instead of running macros, malicious actors are now creating Word documents with DDE fields that open command prompts and run compromised code. Under normal circumstances, users get two warnings when this happens: one noting that DDE “contains links that may refer to other files” and prompting the user to approve or deny the data update, and another that indicates the remote data is not available and starts a command prompt instead.

Since that second warning throws up red flags, it’s no surprise that cybercriminals found a way to suppress it, leaving only the first notification. This first warning occurs whenever a DDE transfer takes place, meaning that employees who are familiar with the service are likely to ignore the alert, giving attackers the foothold they need.

A Lack of Action

Researchers from security firm SensePost reported the DDE malware attack vector to Microsoft back in August. On Sept. 26, the software giant told SensePost that no further action would be taken and the vulnerability would be considered for a next-version candidate bug.

Why the lack of action? Because the service is working as intended. DDE is old — it was supplanted by OLE more than a decade ago. While it still allows data transfer between Office applications, it comes with a warning prompt that requires user approval.

Put simply, users should know better. There’s only so much software can do before employees are responsible for their own choices.

Another Office-Based Malware Attack

Worth noting is the rise of another Office malware variant known as KnockKnock, which targets Office 365 corporate email accounts such as those for service, automation and marketing, according to Help Net Security. Since these accounts aren’t tied to specific users, they often lack two-factor authentication. If fraudsters manage to break in, they’re able to send legitimate-looking messages networkwide. This is the worst-case scenario for DDE attacks: emails with compromised .doc attachments that seemingly come from internal sources. Users are hard pressed to detect potential problems.

DDE malware attacks highlight the role of user choice, since it’s an outdated technology working as intended and even comes with an unstoppable warning message. No matter how sophisticated malicious software becomes, employees remain the linchpin and the first line of effective malware defense.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today