Friday, December 8, 2023

Hackers Abuse Excel 4.0 Macros to Deliver Malware such as ZLoader & Quakbot

The Excel 4.0 macros are being continuously adapted by the threat actors. recently experts have detected that hackers are abusing Excel 4.0 macros to spread ZLoader and Quakbot malware.

In a report, the cybersecurity researchers stated that Excel4 (XLM) macros are a legacy scripting language that was first launched in 1992. 

The analysts came to know about this malware through a survey of 160,000 Excel 4.0 documents between November 2020 and March 2021. After a proper investigation, they found that 90% of the document files were identified as malicious. 

The Excel macros are quite old, but hackers are targetting them because it provides paths to access all the powerful functionalities like interaction with the operating system (OS).

Statistical Analysis & Data

However, to know all its key details, the experts have downloaded all the documented files of Excel up to November 2020, that consist of nearly 160,000, as we told earlier.

Among all the 160,000 documented files, the users found that 90% of the files have used Excel 4.0 (XLM) macros. But, if users encounter a document that generally contains XLM macros, then it confirms that its macro will be malicious.

According to the cybersecurity researchers, XLM macros are a legacy Office option, and consequently, it provides a small chance that the new documents would use them instead of more “modern” VBA macros.

Quakbot Specimen

After analyzing the malicious attack, the experts came to know that they are dealing with the Quakbot family. Security researchers have described further that the hackers behind Quakbot often distribute all their payloads in the form of an Excel document.

That’s why the hackers try to convince their targets to allow macros so that they can easily decrypt the content. However, the messages that the hackers send are quite convincing, and therefore most of the time, users fall for their trap.


It’s not the first time hackers are abusing Excel 4.0; most of the hackers attack Excel to spread their malware in the whole system.

Moreover, the specialists came to know that the malware fooled the users into allowing macros with convincing messages, but they have also come with embedded files containing XLM macros.

However, these XLM macros download and execute a malicious second-stage payload retrieved from a remote server. That’s why the cybersecurity researchers affirmed that it is very important that Macros should get decrypted as soon as possible.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.


Latest articles

Exploitation Methods Used by PlugX Malware Revealed by Splunk Research

PlugX malware is sophisticated in evasion, as it uses the following techniques to avoid...

TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities

Hackers exploit Outlook and WinRAR vulnerabilities because these widely used software programs are lucrative...

Bluetooth keystroke-injection Flaw: A Threat to Apple, Linux & Android Devices

An unauthenticated Bluetooth keystroke-injection vulnerability that affects Android, macOS, and iOS devices has been...

Atlassian Patches RCE Flaw that Affected Multiple Products

Atlassian has been discovered with four new vulnerabilities associated with Remote Code Execution in...

Reflectiz Introduces AI-powered Insights on Top of Its Smart Alerting System

Reflectiz, a cybersecurity company specializing in continuous web threat management, proudly introduces a new...

SLAM Attack Gets Root Password Hash in 30 Seconds

Spectre is a class of speculative execution vulnerabilities in microprocessors that can allow threat...

Akira Ransomware Exploiting Zero-day Flaws For Organization Network Access

The Akira ransomware group, which first appeared in March 2023, has been identified as...
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Endpoint Strategies for 2024 and beyond

Converge and Defend

What's the pulse of Unified Endpoint Management and Security (UEMS) in Europe? Join us live to uncover the strategies that are defining endpoint security in the region.

Related Articles