October 16, 2017 By Douglas Bonderud 2 min read

Macro-based Microsoft Office malware is a go-to tactic for aspiring cybercriminals because it’s reliable and effective. Since macros remain an integral part of Word documents, many companies don’t disable them by default, and users often open .doc attachments.

But with enterprise IT on the war path for signs of any macro malware attack, criminals are getting creative. According to Bleeping Computer, they’re now using an outdated Office feature known as Dynamic Data Exchange (DDE) to infiltrate and infect corporate devices.

Legacy’s Long Shadow

DDE allows Office applications to cross-load data from each other, which enables Word to quickly grab information from other Office apps. In practice, it’s just a custom field that lets users specify where data is pulled from and what type of data is injected. DDE has since been replaced by Microsoft’s Object Linking and Embedding (OLE) toolkit, but it’s still available on a per-application basis.

Instead of running macros, malicious actors are now creating Word documents with DDE fields that open command prompts and run compromised code. Under normal circumstances, users get two warnings when this happens: one noting that DDE “contains links that may refer to other files” and prompting the user to approve or deny the data update, and another that indicates the remote data is not available and starts a command prompt instead.

Since that second warning throws up red flags, it’s no surprise that cybercriminals found a way to suppress it, leaving only the first notification. This first warning occurs whenever a DDE transfer takes place, meaning that employees who are familiar with the service are likely to ignore the alert, giving attackers the foothold they need.

A Lack of Action

Researchers from security firm SensePost reported the DDE malware attack vector to Microsoft back in August. On Sept. 26, the software giant told SensePost that no further action would be taken and the vulnerability would be considered for a next-version candidate bug.

Why the lack of action? Because the service is working as intended. DDE is old — it was supplanted by OLE more than a decade ago. While it still allows data transfer between Office applications, it comes with a warning prompt that requires user approval.

Put simply, users should know better. There’s only so much software can do before employees are responsible for their own choices.

Another Office-Based Malware Attack

Worth noting is the rise of another Office malware variant known as KnockKnock, which targets Office 365 corporate email accounts such as those for service, automation and marketing, according to Help Net Security. Since these accounts aren’t tied to specific users, they often lack two-factor authentication. If fraudsters manage to break in, they’re able to send legitimate-looking messages networkwide. This is the worst-case scenario for DDE attacks: emails with compromised .doc attachments that seemingly come from internal sources. Users are hard pressed to detect potential problems.

DDE malware attacks highlight the role of user choice, since it’s an outdated technology working as intended and even comes with an unstoppable warning message. No matter how sophisticated malicious software becomes, employees remain the linchpin and the first line of effective malware defense.

More from

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today