Microsoft released a security bulletin to patch CVE-2014-6332, a vulnerability within Windows Object Linking and Embedding that could result in remote code execution if a user views a maliciously crafted web page with Microsoft Internet Explorer. On November 26th, Talos began observing and blocking an attack disguised as a hidden iframe on a compromised domain to leverage this vulnerability. The attackers had inserted malicious code to silently redirect users (without visual indication) to another page containing malware. Since there is no user indication or interaction required, users are unaware that the original host theyve navigated to is compromised.”]
Source: https://blog.talosintelligence.com/2014/12/ancient-mac-site-harbors-botnet-that.html