Advanced Techniques to Execute a Shellcode in Word Memory

Jean Rosemond Dora, Ladislav Hluchý · 2025

Executing a macro from VBA is a crossroad that is very well used in Offensive security since attackers can run the application directly on memory to avoid security alerts. This paper is a continuity (future work) of our previous one at the SACI-2025 conference entitled "Execution of Shellcode in Word Memory". We have encountered an obstacle that needs to be overcome. When we successfully obtained a callback session on the attacking machine (Kali), we could start performing activities such as enumeration, scanning, etc. We could even perform a privilege escalation, by giving ourselves higher access (administrator, NT-authority system). With this done, we could subsequently attempt to laterally move from account to account, from computer to computer whenever and wherever possible, based on the active directory (AD) configuration (See [?]). However, as soon as the victim (the Windows user) closes his MS Word, we automatically lose our session shell, i.e., we lose the connection. In this case, we were very dependent on the victim’s behavior even after getting unauthorized access to his device. Therefore, we certainly need to bypass this challenge and remove this dependency. To do that, we will address new techniques and rebuild our shellcode by calling Win32 APIs from PowerShell rather than VBA. However, this will be done indirectly since PowerShell cannot naturally interact with Win32 APIs. We will use the automigrate module that comes with the Metasploit framework.

Read the paper · More papers on PaperTik