logo

Red team tool ‘MacroPack’ abused in attacks to deploy Brute Ratel

ID: a4a9fd93-fbf3-5999-8071-dd25e5207e0f

STIX ID: report--a4a9fd93-fbf3-5999-8071-dd25e5207e0f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco Talos researchers report that the MacroPack red-team framework is being abused in the wild to generate malicious Office documents that deliver payloads including Havoc, Brute Ratel, and PhantomCore across multiple clusters (China, Pakistan, Russia, U.S.). The documents use multi-stage VBA that loads malicious DLLs, employ obfuscation (Markov-chain renaming, string encoding) and include four consistent non-malicious VBA subroutines that act as a MacroPack Pro fingerprint; observed communications include DoH and CloudFront and targets range from military-themed lures to spoofed forms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.