Remove 06
Remove 2016 Remove Blog Remove Encryption Remove Events Remove Security
article thumbnail

[SI-LAB] FlawedAmmyy Leveraging Undetected XLM Macros as an Infection Vehicle

Security Affairs

This is part of a giant list of Living off the Land (LOL) techniques that attackers employ to mask their activities from runtime endpoint security monitoring tools such as AVs. Next, the user is asked to enable active content, and then the msiexec and subsequent chain of events are automatically executed.