Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro
#1
Information 
Quote:The Gamaredon threat group has given its post-compromise toolset a facelift with the addition of a new Visual Basic for Applications (VBA) macro. The VBA macro leverages compromised victims’ Microsoft Outlook email accounts to send spear-phishing emails to their contacts – rapidly widening the potential attack surface.
 
Researchers say, while abusing a compromised mailbox to send malicious emails is not a new technique, this is the first publicly documented case of an attack group using both an Outlook macro and an OTM file to do so. An OTM file stores macros that are written for Microsoft Outlook.
 
“In the last few months, there has been an increase in activity from this group, with constant waves of malicious emails hitting their targets’ mailboxes,” according to Jean-Ian Boutin, senior malware researcher with ESET, in a Thursday analysis. “The attachments to these emails are documents with malicious macros that, when executed, try to download a multitude of different malware variants.”

After the victim is initially compromised (typically via a spear-phishing email with a malicious attachment), malicious code is first delivered in a 7z self-extracting archive. 7z are compressed archive files created with 7-Zip open source software. The code runs a VBScript that first kills the victim’s Outlook process (if it is running), and then removes any security protections around VBA macro execution in Outlook by changing registry values.

Read more: https://threatpost.com/microsoft-outlook...ro/156484/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
New Windows 11 Update Adds Built-In Sysm...
Microsoft is rolli...harlan4096 — 10:11
Ubuntu 24.04.4 LTS / 25.10
Ubuntu 24.04.4 LTS...harlan4096 — 08:28
HWMonitor 1.62 for Windows
HWMonitor 1.62 for...harlan4096 — 08:26
AnyDesk 9.6.2 for macOS
AnyDesk 9.6.2 for ...harlan4096 — 08:25
uBOLite 2026.211.2314 (already released ...
uBOLite 2026.211.2...harlan4096 — 08:24

[-]
Birthdays
Today's Birthdays
avatar (50)neuthrusBub
avatar (30)script6027529171
Upcoming Birthdays
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (46)dimaWeami
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
There are no staff members currently online.

>