logo

New Voldemort malware abuses Google Sheets to store stolen data

ID: 8c1f1cdf-c63a-514a-b2ba-ac6f2d7c48e8

STIX ID: report--8c1f1cdf-c63a-514a-b2ba-ac6f2d7c48e8

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Voldemort backdoor phishing campaign:** Proofpoint observed a global phishing campaign (began Aug 5, 2024) distributing a previously undocumented C-based backdoor named "Voldemort" via tax-themed lures to over 70 organizations (20,000+ emails, peak ~6,000/day), primarily targeting insurance, aerospace, transportation, and education; attackers use Google AMP/InfinityFree landing pages, search-ms redirection to WebDAV-hosted LNK/ZIP files that trigger a Python loader, DLL side-loading with a legitimate Cisco executable, and Google Sheets as a resilient C2/exfiltration channel; recommended mitigations include restricting external file-sharing, blocking TryCloudflare usage, and monitoring for suspicious PowerShell activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.