APT40 targets defense industry with multi-stage macro-enabled documents

Опубликовано: 04 Апрель 2026
на канале: Prelude
133
6

For this week's TTP Tuesday we are releasing a new APT40 themed chain based on multi-stage macro-enabled Office documents. These documents use LOLBins (living-off-the-land binaries) to download and execute secondary malware. CISA released multiple advisories on APT40 targeting the defense industry in 2017.

This chain chain stages and executes Office documents that contain VBA scripts to run MShta. The HTA file include a script to download and execute a secondary Pneuma agent on the compromised host. To get started, configure your range with the required Operator network facts such as public IP and agent port.

There are several ways to follow us and learn more about Prelude and our team members:

GET OUR PRODUCTS
Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg

JOIN OUR COMMUNITY
Discord:   / discord  
Reddit:   / preludeorg  
Twitter:   / preludeorg  

READ, WATCH, AND LISTEN
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org/
Watch our live streams:   / preludeorg  
Watch our pre-recorded content:    / preludeorg  

FOLLOW OUR TEAM
David:   / privateducky  
Alex:   / khyberspache  
Kris:   / xanthonus  
Octavia:   / vv_x_7  
Sam:   / wasupwithuman