ACT III
Word Up
As of 2022 this course is now free for everyone!
I've decided to make this course free since Malicious Word Documents are becoming a thing of the past.
You should stll complete this course though as it will help develop the cybercriminal mindset and help to sharpen your claws yes? This will help build on what you've already learned and prepare you for the future courses here.
It may seem that these techniques are outdated but don't over look them quite yet. Learning this will be beneficial to you so when an exploit or new technique is revealed you'll be able to act accordingly using these new found skills!
Please note that this course has been heavily modified to reflect the current times! What that means is that most of the example code used throughout the course is pretty lame compared to what is was. I know... but the point is to demonstrate how macros are executed are a victims computer and why they were the best malware delivery method used when targeting someone, or something, with malware.
Don't get upset that malicious Microsoft Word macros are a thing of the past and you were sleeping behind the wheel missing out on easy hacking. You just have to educate yourself on the newest trends and move the fuck on!
===================================================================================
In order to follow this course you need a legitimate copy of Microsoft Office:
- Click on "
File."
- Click on "
Options."
- Click on "
Trust Center."
- Click on "
Trust Center Settings...."
- Finally click on "
Enable all macros (not recommended; potentially dangerous code can run)".
- Then click "
OK".
===================================================================================
Now your Microsoft Word is setup how it was when everyone was getting compromised with malicious documents. It was glorious and easyyyyy. Obviously people using Microsoft Office aren't turning that shit on as it's disabled by default hence why these methods are no longer an option. This course is strictly for learning purposes.
Microsoft pushed an update for Windows Defender in 2021 that effectively killed Windows Word/Excel macros as a delivery mechanism for malware. Basically it changed it so macros are all Disabled by default but this course is still very useful for learning purposes as not everyone is using the most recent version of Word products (they probably are but who knows) and new exploits may be released in the future so do not think that Macros are entirely dead. Meh they are dead but you never know what the future holds.
Click to Read - Microsoft blocks macros
This is a skill that you should have in your toolbox. New exploits come out all the time and who knows what the future holds. Regardless, you should be ready to use this particular skill when you're able to do so!
Click to Read - Microsoft Word Bypass Revealed
Click to Read - Microsoft Word 2024 exploit
Click to Read - Microsoft Word 2026 exploit
It's too bad really. I'm afraid you guys are a little too late to the party when it comes to compromising people through malicious Word documents. Compromising people through this method was the preferred method used by all hacker maniacs a like. To be fair though we all had a good run for the past 15+ years. Makes you wonder why Microsoft took so long to fix?
If you just got into the cybercriminal game now I'm afraid you missed out. Don't worry too much about it though as there are other malware delivery methods being used out there to quench DAT RAT thirst.
If you're familiar with malicious Word documents let me save you some time and confirm the following do
NOT work:
DDE
MagicUnicorn
LuckyStrike
MacroPack
EvilClippy
Office Purge
VBad
VBA Purge/VBA Stomping techniques
Embedding an EXE
The ACT VII - Tale of a RAT course dives deep into current malware delivery methods used by other cybercriminals gangs and nation state actors a like. Something you too will need to learn if you plan on compromising people that interest you!
It's best if you turn off Windows Defender when going through this course to ensure everything works as expected.
This course is made for the average to intermediate level of hacker wanting to learn how to compromise an individual or company with a malicious Microsoft Word document. You'll be learning from real world examples being launched by nation state government hackers as well as from the cyber war happening around us today. These types of hackers are having a lot of success with compromising people and organizations using the tradecraft you're about to learn.
It's easier than ever for anyone to obtain sophisticated malware such as cyptojackers, cryptomining malware, ransomware, and Remote Access Trojans (RAT) to infect whomever they please and begin to generate income for themself easily. Being able to deliver malware to your victims properly is just as important as owning the right malware!
You should purchase malware only for the sole purpose of making money and infecting others. Nothing else!
Well that's my advice to you anyways ;)
Maybe you're unable to code your own RAT or maybe you're broke as fuck so you can't purchase the malware you need. If you can't code one yourself and can't afford to buy some then the only option is to use publicly available malware that everyone else is using. If that's your situation then expect your infection rates to be extremely low and failure will be punching you in the face over and over.
As you progress with your cybercriminal operations you will need proper malware to be successful. There's just no other way. Whatever that costs you is what it's going to cost you. It's that simple. Save up, plan, and execute your operations until you're successful. Or die tryin'.
If you want to make money from hacking you need to be realistic and start focusing on, at minimum Windows 10 (as of October 2023 it's no longer supported by Microsoft), Windows 11, or an updated macOS computer.
Windows users will be protected from most, if not all, publicly available malware thanks to Windows Defender (WD). If you're not familiar with WD it's the most used Windows Anti-Virus (AV) software today, plus it's free. You should assume at minimum that you'll be up against Windows Defender when delivering malware to your targets! We're not going to discuss by-passing every single AV out there so for now we're sticking with the default setups of each OS.
Remember, since Spring 2021 Windows Defender detects all methods that require a VBA to download and execute so you'll need to rely on private exploits or new techniques that might get revealed over time. You want to still learn this all because hacking is about opportunity and if an exploit gets dropped somewhere you'll be in a position to act on it.
Click to Read - Just an exploit away
Push on.
You should be focusing on smaller targets and not targeting Fortune 500 companies.
I suggest learning server-side hacking later on in your cybercriminal career because targeting individuals is much easier from an intermediate level of hacker perspective and does not require much "technical" knowledge. You see? We will get into more advanced stuff as things progress here at HackTown but this is best way in my personal opinion.
I code my own malicious malware tools and I would recommend everyone do so in the future depending on how far you want to take it. If you can't code your own malware then you're going to purchase the right malware you require. Please check the HackTown Armory or The Vault for the newest recommended available malware.
To view all the links throughout this course please ensure your Tor Browser settings are set to "Standard" with JS enabled or alternatively you can view them in a normal browser.
Keep in mind some website providers will block Tor exit nodes from accessing their websites and thus you will not be able to view them properly using the Tor Browser.
It's time to sharpen your hacker claws and compromise the targets that matter to you. Let's get into it maniacs.
Welcome to ACT III.
Click here to begin