Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user.(Citation: SilentBreak Outlook Rules) Once malicious rules have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious rules will execute when an adversary sends a specifically crafted email to the user.(Citation: SilentBreak Outlook Rules)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Detect Persistence via Malicious Outlook Rules
is blocked by Update Software
is blocked by Behavior Prevention on Endpoint
is blocked by Secure Baseline Configurations
is blocked by Phishing & Spam Protection
is blocked by Mobile Code
is blocked by Least Privilege
is blocked by Detonation Chambers (Sandboxes)
is blocked by Software & Firmware Patching
Impressum German English