Hey Dridex, Tu Runā Latviski?

IBM X-Force Research reported that Dridex recently conducted attacks in unlikely areas, such as Latvia, Lithuania, Estonia and Ukraine.

The post Hey Dridex, Tu Runā Latviski? appeared first on Security Intelligence.

Continue reading Hey Dridex, Tu Runā Latviski?

VBA Macro Malware Jumping on the Ransomware Bandwagon

IBM observed a spike in malware activity that uses Visual Basic for Applications (VBA) macros to deliver malicious attachments.

The post VBA Macro Malware Jumping on the Ransomware Bandwagon appeared first on Security Intelligence.

Continue reading VBA Macro Malware Jumping on the Ransomware Bandwagon

VBA Macro Malware Jumping on the Ransomware Bandwagon

IBM observed a spike in malware activity that uses Visual Basic for Applications (VBA) macros to deliver malicious attachments.

The post VBA Macro Malware Jumping on the Ransomware Bandwagon appeared first on Security Intelligence.

Continue reading VBA Macro Malware Jumping on the Ransomware Bandwagon

Donoff Macro Dropping Ransomware

Recently, we’ve spotted Zepto ransomware spreading through spam email containing fake invoices (see image below). These attachments contain a Macro-Enabled word document file known as Donoff, which downloads the Zepto executable that encrypts all your files and will later ask for payment of the decryption key. We decided to take a closer look on the Donoff […]

The post Donoff Macro Dropping Ransomware appeared first on ThreatTrack Security Labs Blog.

Continue reading Donoff Macro Dropping Ransomware

Where’s the Macro? Malware authors are now using OLE embedding to deliver malicious files

Recently, we’ve seen reports of malicious files that misuse the legitimate Office object linking and embedding (OLE) capability to trick users into enabling and downloading malicious content. Previously, we’ve seen macros used in a similar matter, and this use of OLE might indicate a shift in behavior as administrators and enterprises are mitigating against this… Continue reading Where’s the Macro? Malware authors are now using OLE embedding to deliver malicious files