Skip to main content
← Back to Demos
Macro intermediate · 15 min

RTF document embedding OLE object that executes on open

Rich Text Format documents are a classic initial-access vehicle because they can embed OLE objects - embedded documents, spreadsheets, or executables that the host application activates when the user double-clicks the embedded icon (MITRE T1204.002). An attacker can hide a malicious object inside an otherwise legitimate-looking RTF so the weaponized content ships in a format that many email and web filters pass without deep inspection. Deep CDR disassembles the RTF structure, extracts the embedded object, inspects it, and rebuilds a sanitized document with the OLE object neutralized - the user still sees the content, but nothing executes on open. The demo embeds a benign OLE object that only invokes Calculator, so it is safe to run on any Windows system.

Attack Technique

RTF OLE object

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.rtf

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---