October 16, 2017 By Douglas Bonderud 2 min read

Macro-based Microsoft Office malware is a go-to tactic for aspiring cybercriminals because it’s reliable and effective. Since macros remain an integral part of Word documents, many companies don’t disable them by default, and users often open .doc attachments.

But with enterprise IT on the war path for signs of any macro malware attack, criminals are getting creative. According to Bleeping Computer, they’re now using an outdated Office feature known as Dynamic Data Exchange (DDE) to infiltrate and infect corporate devices.

Legacy’s Long Shadow

DDE allows Office applications to cross-load data from each other, which enables Word to quickly grab information from other Office apps. In practice, it’s just a custom field that lets users specify where data is pulled from and what type of data is injected. DDE has since been replaced by Microsoft’s Object Linking and Embedding (OLE) toolkit, but it’s still available on a per-application basis.

Instead of running macros, malicious actors are now creating Word documents with DDE fields that open command prompts and run compromised code. Under normal circumstances, users get two warnings when this happens: one noting that DDE “contains links that may refer to other files” and prompting the user to approve or deny the data update, and another that indicates the remote data is not available and starts a command prompt instead.

Since that second warning throws up red flags, it’s no surprise that cybercriminals found a way to suppress it, leaving only the first notification. This first warning occurs whenever a DDE transfer takes place, meaning that employees who are familiar with the service are likely to ignore the alert, giving attackers the foothold they need.

A Lack of Action

Researchers from security firm SensePost reported the DDE malware attack vector to Microsoft back in August. On Sept. 26, the software giant told SensePost that no further action would be taken and the vulnerability would be considered for a next-version candidate bug.

Why the lack of action? Because the service is working as intended. DDE is old — it was supplanted by OLE more than a decade ago. While it still allows data transfer between Office applications, it comes with a warning prompt that requires user approval.

Put simply, users should know better. There’s only so much software can do before employees are responsible for their own choices.

Another Office-Based Malware Attack

Worth noting is the rise of another Office malware variant known as KnockKnock, which targets Office 365 corporate email accounts such as those for service, automation and marketing, according to Help Net Security. Since these accounts aren’t tied to specific users, they often lack two-factor authentication. If fraudsters manage to break in, they’re able to send legitimate-looking messages networkwide. This is the worst-case scenario for DDE attacks: emails with compromised .doc attachments that seemingly come from internal sources. Users are hard pressed to detect potential problems.

DDE malware attacks highlight the role of user choice, since it’s an outdated technology working as intended and even comes with an unstoppable warning message. No matter how sophisticated malicious software becomes, employees remain the linchpin and the first line of effective malware defense.

More from

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

What’s behind unchecked CVE proliferation, and what to do about it

4 min read - The volume of Common Vulnerabilities and Exposures (CVEs) has reached staggering levels, placing immense pressure on organizations' cyber defenses. According to SecurityScorecard, there were 29,000 vulnerabilities recorded in 2023, and by mid-2024, nearly 27,500 had already been identified.Meanwhile, Coalition's 2024 Cyber Threat Index forecasts that the total number of CVEs for 2024 will hit 34,888—a 25% increase compared to the previous year. This upward trend presents a significant challenge for organizations trying to manage vulnerabilities and mitigate potential exploits.What’s behind…

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today