Security News > 2023 > February > Hackers weaponize Microsoft Visual Studio add-ins to push malware

Hackers weaponize Microsoft Visual Studio add-ins to push malware
2023-02-02 20:23

Security researchers warn that hackers may start using Microsoft Visual Studio Tools for Office more often as method to achieve persistence and execute code on a target machine via malicious Office add-ins.

NET-based malware and embedding it into the Office add-in.

VSTO is a software development kit, part of Microsoft's Visual Studio IDE. It is used to build VSTO add-ins, which are extensions for Office applications that can execute code on the machine.

These add-ins can be packaged with the document files or downloaded from a remote location and are executed when launching the document with the associated Office app.

Deep Instinct noticed some attacks using remote VSTO add-ins.

In one attack that Deep Instinct saw targeting users in Spain, the add-in payload executed an encoded and compressed PowerShell script on the computer.


News URL

https://www.bleepingcomputer.com/news/security/hackers-weaponize-microsoft-visual-studio-add-ins-to-push-malware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 681 810 4511 4178 3707 13206