Epic Manchego gang uses Excel docs that avoid detectionSecurity Affairs·Sep 7, 08:01 UTC · Sep 7, 2020Malware30
“Red October”. Detailed Malware Description 1. First Stage of AttackKaspersky Securelist·Jan 17, 16:09 UTC · Jan 17, 2013MalwareCVE-2009-3129CVE-2010-3333CVE-2012-0158+1 CVEs47
FlawedAmmyy Leveraging Undetected XLM Macros as an Infection VehicleSecurity Affairs·Mar 2, 18:46 UTC · Mar 2, 2019Malware in the wild157
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy MalwareThe Hacker News·Feb 25, 15:54 UTC · Feb 25, 2025Malware55
LimeRAT malware delivered using 8-yearSecurity Affairs·Apr 1, 08:00 UTC · Apr 1, 2020MalwareCVE-2012-015835
Malicious spam campaigns delivering banking TrojansKaspersky Securelist·Jun 24, 10:00 UTC · Jun 24, 2021Malware42
Cybercriminals Widely Abusing Excel 4.0 Macro to Distribute MalwareThe Hacker News·Apr 28, 13:43 UTC · Apr 28, 2021Malware42
Public report on attacks in Middle East we attribute to WIRTE APTKaspersky Securelist·Nov 29, 08:00 UTC · Nov 29, 2021Malware42
Microsoft warns TA505 changed tactic in an ongoing malware campaignSecurity Affairs·Feb 2, 09:52 UTC · Feb 2, 2020Malware42
Friday Squid Blogging: How the Squid Lost Its ShellSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Malware30
DarkGate switches up its tactics with new payload, email templatesCisco Talos·Jun 5, 12:00 UTC · Jun 5, 2024Malware30
Mavenir announces the expansion of European capabilities to support Open RAN end-to-end deliveryHelp Net Security·Jan 10, 13:58 UTC · Jan 10, 2024Malware30
Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT MalwareThe Hacker News·Nov 11, 06:13 UTC · Nov 11, 2024MalwareCVE-2017-019947
BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documentsKaspersky Securelist·Jan 28, 11:01 UTC · Jan 28, 2016Malware55
UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting UkraineThe Hacker News·Apr 8, 10:12 UTC · Apr 8, 2025Malware30
New AI-Developed Malware Campaign Targets Iranian ProtestsInfosecurity Magazine·Jan 30, 11:55 UTC · Jan 30, 2026Malware42
Excellent Write-up of the SolarWinds Security BreachSchneier on Security·Aug 30, 11:24 UTC · Aug 30, 2021Malware42
Hackers Use New Trick to Disable Macro Security Warnings in Malicious Office FilesThe Hacker News·Jul 9, 07:53 UTC · Jul 9, 2021Malware30
Layered security becomes critical as malware attacks riseHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2020Malware55
Exclusive: spreading CSV Malware via Google SheetsSecurity Affairs·Jan 31, 11:23 UTC · Jan 31, 2019MalwareCVE-2014-352435
Ukraine Warns of CABINETRAT Backdoor + XLL AddThe Hacker News·Oct 1, 07:11 UTC · Oct 1, 2025Malware42
Ghostwriter Cyber-Attack Targets Ukrainian, Belarusian OppositionInfosecurity Magazine·Feb 25, 15:30 UTC · Feb 25, 2025Malware30
You may trust your users, but can you trust their files?Help Net Security·Jan 16, 12:44 UTC · Jan 16, 2023Malware30
Emotet Now Using Unconventional IP Address Formats to Evade DetectionThe Hacker News·Jan 26, 05:21 UTC · Jan 26, 2022Malware30
TA505 cybercrime group use SDBbot RAT in recent campaignsSecurity Affairs·Oct 20, 17:57 UTC · Oct 20, 2019Malware42
Chinese Actors Use ‘3102’ Malware in Attacks on US Government and EU MediaPalo Alto Unit 42·Nov 1, 09:52 UTC · Nov 1, 2018MalwareCVE-2012-015835
MartyMcFly Malware: new Cyber-Espionage Campaign targeting Italian Naval IndustrySecurity Affairs·Oct 17, 19:14 UTC · Oct 17, 2018MalwareCVE-2017-1188235
Malware campaign targets RussianSecurity Affairs·Aug 11, 08:45 UTC · Aug 11, 2017MalwareCVE-2017-019947
IcedID malware gang positioning itself as one of the Emotet replacementsThe Record·Jun 25, 00:00 UTC · Jun 25, 2026Malware42
GIFTEDCROOK Malware Evolves: From Browser Stealer to IntelligenceThe Hacker News·Jun 28, 08:00 UTC · Jun 28, 2025Malware30
A new fileless variant of Remcos RAT observed in the wildSecurity Affairs·Nov 11, 14:46 UTC · Nov 11, 2024MalwareCVE-2017-019947
DarkGate Malware Replaces AutoIt with AutoHotkey in Latest Cyber AttacksThe Hacker News·Jun 6, 04:40 UTC · Jun 6, 2024MalwareCVE-2023-36025CVE-2024-2141235