Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack
ID: ff990b29-b4a2-45f9-be86-b92b82af9a6e
STIX ID: report--ff990b29-b4a2-45f9-be86-b92b82af9a6e
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2017-11-08
Last Modified Date: 2017-11-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
McAfee Labs reports that APT28 distributed malicious Word documents (e.g., IsisAttackInNewYork.docx, SaberGuardian2017.docx) which use Microsoft Office DDE to execute PowerShell, download the Seduploader DLL payload (vms.dll/secnt.dll), and establish control via domains such as webviewres.net and netmediaresources.com; the report includes file hashes, compile dates, control servers, IPs, and analysis linking the samples to previous APT28 activity and techniques.
