HomeSecurityAvaddon ransomware: Attacks through Excel 4.0 macros

Avaddon ransomware: Attacks through Excel 4.0 macros

Microsoft announced yesterday that Avaddon ransomware spread this week using an old technique that has resurfaced. Attacks using this ransomware appear to be more targeted, relying on malicious Excel 4.0 macros to download the malware directly to a system.

This is a campaign that was centered in Italy. Specifically, this file-encrypting malware appeared in early June, infecting users as part of a massive spam campaign .Malware operators are recruiting collaborators to spread the ransomware payload.

excel 4.0

Microsoft Security Intelligence pointed out that the latest effort by the hackers behind this campaign had specific targets mainly in Italy, while sending emails with files containing malicious Excel 4.0 macros.

avaddon

One such email, found by a malware hunter named JamesWT_MHT, is presented in the form of a notification supposedly from the Labor Inspectorate and addressed to a small business, wanting to inform it about workplace violations during a period of crisis, such as the ongoing COVID -19 pandemic . The purpose of the emails is supposedly to warn their recipients of impending sanctions and possible legal actions. In addition, there is a ZIP file in the attachment named “Official Notice”. The attachment also contains an Excel 4.0 (XML) macro, which is also compatible with modern software where VBA code is used

When executed, the macro directly downloads a sample of Avaddon ransomware, without an intermediate downloader. This is a technique that has been observed in other file-encrypting malicious actors recently. The use of the old macro is effective. The choice of Excel 4.0 macros to spread the malware may seem strange, given that it was released in Microsoft Office 28 years ago. However, Avaddon and many other malicious actors have recently started using them.

avaddon ransomware

In the case of Avaddon, this appears to be working as the ID Ransomware website received a large number of submissions from targeted victims. The spike occurred on June 18, 28, and 30, which is consistent with Microsoft’s observations. While this is an old technique, malicious Excel 4.0 macros have become increasingly popular in malware campaigns in recent months. This technique has been adopted by many campaigns, including those exploiting the COVID-19 pandemic to trick potential victims.


Released in 1992, Excel 4.0 uses XML-based macros that store functions in BIFF (Binary Interchange File Format) files. Therefore, they are much more difficult to parse, compared to the VBA macros used by Excel 5.0.

Microsoft has noticed an increase in malware email campaigns using Excel 4.0 macros in recent months, while noting that since April, the group behind the Avaddon ransomware campaign began using COVID-19 as "bait" to attract potential victims.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS