RTF document embedding OLE object that executes on open
Rich Text Format documents are a classic initial-access vehicle because they can embed OLE objects - embedded documents, spreadsheets, or executables that the host application activates when the user double-clicks the embedded icon (MITRE T1204.002). An attacker can hide a malicious object inside an otherwise legitimate-looking RTF so the weaponized content ships in a format that many email and web filters pass without deep inspection. Deep CDR disassembles the RTF structure, extracts the embedded object, inspects it, and rebuilds a sanitized document with the OLE object neutralized - the user still sees the content, but nothing executes on open. The demo embeds a benign OLE object that only invokes Calculator, so it is safe to run on any Windows system.
Attack Technique
RTF OLE object
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗