
Trojanised Office Tool Hides Multi-Stage Intrusion Behind Streaming C2
A piracy-distributed OfficeRTool archive spanning versions 10.7 through 16.2.0 carries a vhash-identical PowerShell downloader, sandbox-evading VBScript components, and a command-and-control channel engineered to mimic HLS media streaming traffic. The campaign layers legitimacy signals at every stage — a convincing lure, a genuinely signed reconnaissance binary, and TLS-provisioned infrastructure — with a cert-serial pivot tying the C2 to a freshly registered streaming subdomain targeting government environments.
A trojanised version of OfficeRTool — a popular Microsoft Office removal and activation utility distributed through piracy channels — is serving as the entry point for a disciplined, multi-phase intrusion operation that layers sandbox-evading VBScript components, a vhash-identical PowerShell downloader maintained across at least six major tool versions, expired-certificate network reconnaissance, and a command-and-control channel engineered to look indistinguishable from HLS media streaming…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read