Stats
- First seen
- February 2022
- Last seen
- October 2026
Description
Detects documents using dynamic data exchange fields to execute commands without macros. Opening the document runs the embedded command through the protocol handler, a technique documented by researchers and used in phishing campaigns to bypass macro defenses.