Categories: Malware

Hackers Abuse Excel 4.0 Macros to Deliver Malware such as ZLoader & Quakbot

The Excel 4.0 macros are being continuously adapted by the threat actors. recently experts have detected that hackers are abusing Excel 4.0 macros to spread ZLoader and Quakbot malware.

In a report, the cybersecurity researchers stated that Excel4 (XLM) macros are a legacy scripting language that was first launched in 1992. 

The analysts came to know about this malware through a survey of 160,000 Excel 4.0 documents between November 2020 and March 2021. After a proper investigation, they found that 90% of the document files were identified as malicious. 

The Excel macros are quite old, but hackers are targetting them because it provides paths to access all the powerful functionalities like interaction with the operating system (OS).

Statistical Analysis & Data

However, to know all its key details, the experts have downloaded all the documented files of Excel up to November 2020, that consist of nearly 160,000, as we told earlier.

Among all the 160,000 documented files, the users found that 90% of the files have used Excel 4.0 (XLM) macros. But, if users encounter a document that generally contains XLM macros, then it confirms that its macro will be malicious.

According to the cybersecurity researchers, XLM macros are a legacy Office option, and consequently, it provides a small chance that the new documents would use them instead of more “modern” VBA macros.

Quakbot Specimen

After analyzing the malicious attack, the experts came to know that they are dealing with the Quakbot family. Security researchers have described further that the hackers behind Quakbot often distribute all their payloads in the form of an Excel document.

That’s why the hackers try to convince their targets to allow macros so that they can easily decrypt the content. However, the messages that the hackers send are quite convincing, and therefore most of the time, users fall for their trap.

Outcome

It’s not the first time hackers are abusing Excel 4.0; most of the hackers attack Excel to spread their malware in the whole system.

Moreover, the specialists came to know that the malware fooled the users into allowing macros with convincing messages, but they have also come with embedded files containing XLM macros.

However, these XLM macros download and execute a malicious second-stage payload retrieved from a remote server. That’s why the cybersecurity researchers affirmed that it is very important that Macros should get decrypted as soon as possible.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations by…

1 day ago

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the notorious…

2 days ago

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical letters…

2 days ago

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer malware,…

2 days ago

New PyPI Malware Targets Developers to Steal Ethereum Wallets

A recent discovery by the Socket Research Team has unveiled a malicious PyPI package named…

2 days ago

Threat Actors Exploit PHP-CGI RCE Vulnerability to Attack Windows Machines

A recent cybersecurity threat has emerged where unknown attackers are exploiting a critical remote code…

2 days ago