Kaspersky researchers discovered a new attack technique leveraging an undocumented Word feature to gather information on users. The attackers sent phishing emails using Word documents in OLE2 format and contained links to PHP scripts hosted on third-party web resources. Once opened Word sends a GET request to an internal link, which sent information about the software installed on the victim machine to the attackers, including info about which version of Microsoft Office was installed. The researchers noticed the presence of an INCLUDEPICTURE field that indicates that an image is attached to certain characters in the text.”]
Source: http://securityaffairs.co/wordpress/63158/hacking/undocumented-word-feature-attack.html

