logo

Cisco: MS Word Macro Attacks Still Work Just Fine

ID: 8a48ba5c-982a-5622-8124-9271c447ca19

STIX ID: report--8a48ba5c-982a-5622-8124-9271c447ca19

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2014-06-30

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

Cisco describes the "String of Paerls" campaign targeting research and industrial manufacturing organizations that begins with a malicious Microsoft Word document containing a Visual Basic macro which downloads and executes a payload hosted on Dropbox. The actor has evaded detection by rotating domains, varying payloads, and operating for years with low antivirus detection rates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.