FlawedAmmyy Leveraging Undetected XLM Macros as an Infection VehicleSecurity Affairs·Mar 2, 18:46 UTC · Mar 2, 2019Malware in the wild157
Macro Intruders: Sneaking Past Office DefensesCisco Talos·Aug 2, 13:42 UTC · Aug 2, 2016Exploit / PoC in the wild60
Muddying the Water: Targeted Attacks in the Middle EastPalo Alto Unit 42·Nov 14, 21:00 UTC · Nov 14, 2017Data breach57
TAG-110 Targets Tajikistan: New Macro Word Documents Phishing TacticsRecorded Future·Dec 24, 00:00 UTC · Dec 24, 2024Phishing & fraud30
New Techniques to Uncover and Attribute Cobalt Gang Commodity Builders and Infrastructure RevealedPalo Alto Unit 42·Nov 5, 08:54 UTC · Nov 5, 2018VulnerabilityCVE-2017-019935
The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth BackdoorPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Malware42
VileRAT: DeathStalker’s continuous strike at foreign and cryptocurrency exchangesKaspersky Securelist·Aug 10, 11:50 UTC · Aug 10, 2022Malware42
OilRig Actors Provide a Glimpse into Development and Testing EffortsPalo Alto Unit 42·Nov 1, 10:24 UTC · Nov 1, 2018Threat actor45
Hackers use a new technique in malspam campaigns to disable Macro security warnings in weaponized docsSecurity Affairs·Jul 9, 14:19 UTC · Jul 9, 2021Threat actor45
Microsoft to disable Excel 4.0 macros, one of the most abused Office featuresThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Ransomware57
Threat Spotlight: XLLing in Excel - threat actors using malicious addCisco Talos·Dec 20, 13:00 UTC · Dec 20, 2022Threat actor45
Hacker use of Microsoft macros plummeted after default block: reportThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Ransomware57
Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ TrojanPalo Alto Unit 42·Dec 11, 14:41 UTC · Dec 11, 2018Malware30
87% Of The Ransomware Found On The Dark Web Has Been Delivered Via Malicious MacrosHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2022Ransomware57
Hackers Use New Trick to Disable Macro Security Warnings in Malicious Office FilesThe Hacker News·Jul 9, 07:53 UTC · Jul 9, 2021Malware30
What did DeathStalker hide between two ferns?Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2020Malware42
Comnie Continues to Target Organizations in East AsiaPalo Alto Unit 42·Nov 1, 11:01 UTC · Nov 1, 2018Malware42
Microsoft to block internet macros by default in five Office applicationsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability130
Dark Web Research Suggests 87% of Ransomware Brands Exploit Malicious MacrosInfosecurity Magazine·Aug 2, 14:45 UTC · Aug 2, 2022Ransomware57
Attackers are slowly abandoning malicious macrosHelp Net Security·Jul 29, 00:00 UTC · Jul 29, 2022Malware30
URSNIF spam campaign expose new macro evasion tacticsSecurity Affairs·Oct 20, 08:34 UTC · Oct 20, 2017Threat actor45
Word documents laced with malicious macros used to hack Apple Mac systemsSecurity Affairs·Feb 13, 10:14 UTC · Feb 13, 2017Vulnerability42
Microsoft Disables Internet Macros in Office Apps by Default to Block Malware AttacksThe Hacker News·Feb 10, 06:39 UTC · Feb 10, 2022Malware30
Watch Out! First-Ever Word Macro Malware for Apple Mac OS Discovered in the WildThe Hacker News·Feb 10, 03:24 UTC · Feb 10, 2017Malware in the wild57
Spam and Phishing in the First Quarter of 2015Kaspersky Securelist·May 13, 12:00 UTC · May 13, 2015Phishing & fraud30
Unique Office Loader Deploying Multiple Malware FamiliesPalo Alto Unit 42·Jan 28, 20:35 UTC · Jan 28, 2022Malware30
A taste of the latest release of QakBot...........................Security Affairs·May 6, 09:22 UTC · May 6, 2021Ransomware57
Dutch police arrested the author of Dryad and Rubella Macro BuildersSecurity Affairs·Jul 19, 18:08 UTC · Jul 19, 2019Policy & legal42
Ursnif: The Latest Evolution of the Most Popular Banking MalwareSecurity Affairs·Apr 5, 12:57 UTC · Apr 5, 2019Malware30
MS Office Built-In Feature Could be Exploited to Create SelfThe Hacker News·Nov 23, 15:38 UTC · Nov 23, 2017Ransomware in the wild60
VB Dropper and Shellcode for Hancitor Reveal New Techniques Behind UptickPalo Alto Unit 42·Jan 28, 20:40 UTC · Jan 28, 2022Malware30
A year of Fajan evolution and Bloomberg themed campaignsCisco Talos·Apr 21, 11:59 UTC · Apr 21, 2021Threat actor45
A Brand New Ursnif/ISFB Campaign Targets Italian OrganizationsSecurity Affairs·Apr 17, 15:05 UTC · Apr 17, 2020Threat actor45
BlackEnergy APT Attacks in Ukraine employ spearphishing with Word documentsKaspersky Securelist·Jan 28, 11:01 UTC · Jan 28, 2016Malware55
Cybercriminals have adapted since Microsoft's decision to block macrosCyberScoop·May 12, 14:00 UTC · May 12, 2023Ransomware in the wild60