logo

Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack

ID: 5b56c5df-060b-45c0-84f8-677e6eda146a

STIX ID: report--5b56c5df-060b-45c0-84f8-677e6eda146a

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2018-02-04

Last Modified Date: 2018-02-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee analysts observed APT28 distributing malicious Word documents themed around a recent NYC terror attack that abuse Office's DDE feature to run PowerShell and download the Seduploader reconnaissance DLL (vms.dll / secnt.dll). The report includes technical details of the DDE/PowerShell commands, decoded scripts, compile dates, control domains/IPs, SHA1 hashes, and notes the actor likely uses Seduploader as a first-stage implant before deploying X-Agent or Sedreco.