Exploit:Win32/Apptom.gen is the detection name associated with in-the-wild exploitation of CVE-2009-0556, a memory corruption vulnerability in legacy Microsoft PowerPoint. The flaw is triggered by a crafted .ppt file containing an invalid index in the OutlineTextRefAtom, leading to improper memory handling and allowing arbitrary code execution when the file is opened. Reported exploitation occurred in April 2009. Affected products mentioned in the content are Microsoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac. Successful exploitation can allow full compromise of the affected system with the privileges of the current user; impact is greater for users with administrative rights. The content does not attribute this exploit to a specific threat actor and does not provide specific indicators of compromise beyond the exploit name and its use of malicious PowerPoint files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit:Win32/Apptom.gen is an exploit targeting a memory corruption vulnerability in Microsoft PowerPoint, allowing remote code execution when a user opens a specially crafted .ppt file.
Exploit:Win32/Apptom.gen is a malware exploit that was used in the wild to target the Microsoft PowerPoint CVE-2009-0556 vulnerability, enabling remote code execution via malicious PowerPoint files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.