Hackers Abuse Excel 4.0 Macros to Deliver Malware such as ZLoader & Quakbot

The Excel 4.0 macros are being continuously adapted by the threat actors. recently experts have detected that hackers are abusing Excel 4.0 macros to spread ZLoader and Quakbot malware.

In a report, the cybersecurity researchers stated that Excel4 (XLM) macros are a legacy scripting language that was first launched in 1992. 

The analysts came to know about this malware through a survey of 160,000 Excel 4.0 documents between November 2020 and March 2021. After a proper investigation, they found that 90% of the document files were identified as malicious. 

The Excel macros are quite old, but hackers are targetting them because it provides paths to access all the powerful functionalities like interaction with the operating system (OS).

Statistical Analysis & Data

However, to know all its key details, the experts have downloaded all the documented files of Excel up to November 2020, that consist of nearly 160,000, as we told earlier.

Among all the 160,000 documented files, the users found that 90% of the files have used Excel 4.0 (XLM) macros. But, if users encounter a document that generally contains XLM macros, then it confirms that its macro will be malicious.

According to the cybersecurity researchers, XLM macros are a legacy Office option, and consequently, it provides a small chance that the new documents would use them instead of more “modern” VBA macros.

Quakbot Specimen

After analyzing the malicious attack, the experts came to know that they are dealing with the Quakbot family. Security researchers have described further that the hackers behind Quakbot often distribute all their payloads in the form of an Excel document.

That’s why the hackers try to convince their targets to allow macros so that they can easily decrypt the content. However, the messages that the hackers send are quite convincing, and therefore most of the time, users fall for their trap.

Outcome

It’s not the first time hackers are abusing Excel 4.0; most of the hackers attack Excel to spread their malware in the whole system.

Moreover, the specialists came to know that the malware fooled the users into allowing macros with convincing messages, but they have also come with embedded files containing XLM macros.

However, these XLM macros download and execute a malicious second-stage payload retrieved from a remote server. That’s why the cybersecurity researchers affirmed that it is very important that Macros should get decrypted as soon as possible.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Cisco IP Phone Vulnerability Let Attackers Trigger DoS Attack

Cisco has disclosed multiple vulnerabilities in its IP Phone firmware that could severely impact users by allowing unauthenticated, remote attackers…

44 mins ago

Threat Actors Renting Out Compromised Routers To Other Criminals

APT actors and cybercriminals both exploit proxy anonymization layers and VPN nodes to mask their malicious activities, while Pawn Storm,…

53 mins ago

New “Goldoon” Botnet Hijacking D-Link Routers to Use for Other Attacks

Security researchers at FortiGuard Labs discovered a new botnet in April that exploits a weakness in D-Link devices. Dubbed "Goldoon,"…

2 hours ago

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series A funding led by Glilot+, the…

17 hours ago

GoldDigger Malware Using Deep Fake AI Photos To Hijack Bank Accounts

Hackers use deep fake AI photos to impersonate individuals online, allowing them to deceive, manipulate, or gain unauthorized access to…

17 hours ago

Cuttlefish 0-click Malware Hijacks Routers & Captures Data

Cuttlefish is a new malware platform that has been identified to be active since at least July 2023. This malware…

17 hours ago