logo

XLSM Malware with MacroSheets

ID: 11e7fb80-d5b9-5302-be8a-6ccbe584995d

STIX ID: report--11e7fb80-d5b9-5302-be8a-6ccbe584995d

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-08-06

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee technical analysis documents a surge in XLSM/macro-sheet Excel malware that embeds obfuscated formulas and macros to download and execute DLL payloads (e.g., Qakbot and other banking/infostealer families). The report explains XLSM structure and macrosheet obfuscation, presents an infection chain and a sample SHA256, maps relevant MITRE ATT&CK techniques, and provides detection and mitigation guidance for endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.