Netskope Threat Labs reported a campaign using malicious Web Page Archive files (.mht/.mhtml), often delivered inside RAR archives, to infect Microsoft Word users with a DLL backdoor. The attack abuses the Windows Zone.Identifier alternate data stream by setting ZoneId=2, causing the archive to appear trusted enough for Word to open with fewer warnings. Once opened, the lure document uses password-protected and obfuscated VBA macros to drop, repair, rename, and execute the payload while displaying a decoy document to the victim.
The final payload is a packed 64-bit DLL named background.dll that establishes persistence through a scheduled task called Winrar Update, injects into a long-running rundll32.exe process, and collects host and file-system information before encrypting and exfiltrating it to command-and-control infrastructure hosted on Glitch. Microsoft documentation identifies Zone.Identifier as the stream name used to store zone information in Windows, supporting the mechanism abused in the campaign. Netskope said the tradecraft overlaps with earlier activity linked to APT32/Ocean Lotus, including prior use of Web Archive delivery and a similar backdoor seen in 2021.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Netskope said the campaign shared similarities with prior activity linked to APT32/Ocean Lotus, including a similar backdoor observed in August 2021 and earlier use of Web Archive delivery.
Netskope Threat Labs reported a campaign using RAR-packaged .mht/.mhtml Web Page Archive files to deliver infected Microsoft Word documents that relied on trusted Zone.Identifier values and malicious VBA macros to install a DLL backdoor. Netskope also reported the Glitch-hosted command-and-control URLs to Glitch's abuse team, which removed them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.