Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
ID: 5b56c5df-060b-45c0-84f8-677e6eda146a
STIX ID: report--5b56c5df-060b-45c0-84f8-677e6eda146a
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-02-04
Last Modified Date: 2018-02-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee analysts observed APT28 distributing malicious Word documents themed around a recent NYC terror attack that abuse Office's DDE feature to run PowerShell and download the Seduploader reconnaissance DLL (vms.dll / secnt.dll). The report includes technical details of the DDE/PowerShell commands, decoded scripts, compile dates, control domains/IPs, SHA1 hashes, and notes the actor likely uses Seduploader as a first-stage implant before deploying X-Agent or Sedreco.
