Umbra Wiki technique technique/T1137.003
Back to wiki

T1137.003 — Outlook Forms

provenance: imported · ATT&CK: T1137.003

T1137.003: Outlook Forms

MITRE ATT&CK® Enterprise technique

Tactics Persistence
Platforms Windows, Office Suite
Permissions required
Version 1.2
Parent technique T1137

Description

Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and functionality in Outlook messages. Custom Outlook forms can be created that will execute code when a specifically crafted email is sent by an adversary utilizing the same custom Outlook form.(Citation: SensePost Outlook Forms)

Once malicious forms have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious forms will execute when an adversary sends a specifically crafted email to the user.(Citation: SensePost Outlook Forms)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1137/003
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/