logo

Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack

ID: ff990b29-b4a2-45f9-be86-b92b82af9a6e

STIX ID: report--ff990b29-b4a2-45f9-be86-b92b82af9a6e

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2017-11-08

Last Modified Date: 2017-11-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Labs reports that APT28 distributed malicious Word documents (e.g., IsisAttackInNewYork.docx, SaberGuardian2017.docx) which use Microsoft Office DDE to execute PowerShell, download the Seduploader DLL payload (vms.dll/secnt.dll), and establish control via domains such as webviewres.net and netmediaresources.com; the report includes file hashes, compile dates, control servers, IPs, and analysis linking the samples to previous APT28 activity and techniques.