APTMembers
APT

Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2

A piracy-distributed OfficeRTool archive spanning versions 10.7 through 16.2.0 carries a vhash-identical PowerShell downloader, sandbox-evading VBScript components, and a command-and-control channel engineered to mimic HLS media streaming traffic. The campaign layers legitimacy signals at every stage — a convincing lure, a genuinely signed reconnaissance binary, and TLS-provisioned infrastructure — with a cert-serial pivot tying the C2 to a freshly registered streaming subdomain targeting government environments.

May 27, 2026, 06:02 (UTC+9)Last seenMay 27, 2026Severity65ByCTX TeamActorLockbit GangIOC20MITRE11

A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence