Microsoft Excel Files Increasingly Used To Spread Malware
Windows Metastealer Malware Sans Internet Storm Center Now it seems that it is becoming more and more popular to spread malware using malicious excel files. lately, fortinet has collected a number of email samples with excel files attached (.xls, .xlsm) that spread malware by executing malicious vba (visual basic for applications) code. In the spring of 2024, the unit 42 team observed a new offensive campaign weaponizing microsoft excel and leveraging servers with open samba file shares to host files used for spreading darkgate malware. initially targeting the u.s., the campaign gradually expanded to europe and parts of asia.
Dynamically Analyzing A Heavily Obfuscated Excel 4 Macro Malicious File The attack uses an email phishing lure disguised as a shipping purchase order with a malicious microsoft excel spreadsheet attached. once the spreadsheet is downloaded and opened, it exploits a remote code execution vulnerability (cve 2017 0199) to download an html application. Starting around 8 pm gmt 8 on april 16, 2025, macro enabled excel files with extensions such as .xlsm, .xlsb, or .xls began being automatically flagged as malware, specifically identified as x97m slacker.gen!a—when opened or edited in sharepoint, onedrive, or teams. During the campaign, darkgate operators used microsoft excel files (.xlsx) to lure victims into downloading malware from publicly accessible samba file shares. these excel files, often named to appear official or important, contained embedded objects linked to malicious urls. Greetings of the day everyone, in this blog post we are going to analyze a malware sample based based on microsoft excel document. let’s have a closer look and take deep dive into analysis.
Microsoft Excel Files Increasingly Used To Spread Malware During the campaign, darkgate operators used microsoft excel files (.xlsx) to lure victims into downloading malware from publicly accessible samba file shares. these excel files, often named to appear official or important, contained embedded objects linked to malicious urls. Greetings of the day everyone, in this blog post we are going to analyze a malware sample based based on microsoft excel document. let’s have a closer look and take deep dive into analysis. Threat actors used microsoft excel files to spread the darkgate malware in north america, europe and asia through publicly accessible smb file shares in a campaign from march to april 2024. This article reviews a darkgate malware campaign from march april 2024 that uses microsoft excel files to download a malicious software package from public facing smb file shares. Security researchers have identified a malware distribution campaign in which threat actors embed malicious code in microsoft office files to compromise windows systems when documents are opened and macros or embedded scripts are enabled. Threat actors are exploiting weaponized excel spreadsheets to deliver the notorious formbook information stealer malware to windows systems worldwide.
Microsoft Excel Files Increasingly Used To Spread Malware Threat actors used microsoft excel files to spread the darkgate malware in north america, europe and asia through publicly accessible smb file shares in a campaign from march to april 2024. This article reviews a darkgate malware campaign from march april 2024 that uses microsoft excel files to download a malicious software package from public facing smb file shares. Security researchers have identified a malware distribution campaign in which threat actors embed malicious code in microsoft office files to compromise windows systems when documents are opened and macros or embedded scripts are enabled. Threat actors are exploiting weaponized excel spreadsheets to deliver the notorious formbook information stealer malware to windows systems worldwide.
Microsoft Excel Files Increasingly Used To Spread Malware Security researchers have identified a malware distribution campaign in which threat actors embed malicious code in microsoft office files to compromise windows systems when documents are opened and macros or embedded scripts are enabled. Threat actors are exploiting weaponized excel spreadsheets to deliver the notorious formbook information stealer malware to windows systems worldwide.
Microsoft Excel Files Increasingly Used To Spread Malware
Comments are closed.