New malware campaign uses Microsoft Office docs to infect host machines with ObliqueRAT, a remote access Trojan. New method relies on redirecting user to click on malicious link, leading to a valid BMP image. Attackers first have to achieve persistence, which they do by adding a shortcut to the malicious URL into Windows startup. The image hosted on the website also contains executable bytes hidden in the image data bytes, allowing attackers to deploy the trojan. Its an ongoing process, and attackers will likely continue with new techniques and change their M.O to try to stay ahead of the game.”]