Malicious Document Threat
ID: f215979c-36eb-5375-95c3-ec3667b5dab8
STIX ID: report--f215979c-36eb-5375-95c3-ec3667b5dab8
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ documents a recent campaign of weaponized Microsoft Office documents that employ highly obfuscated VBA macros and advanced anti-VM/anti-sandbox checks — including novel techniques such as validating the Office RecentFiles count and querying external IP ownership via a MaxMind API — to avoid automated analysis. When checks pass, the macros download and install payloads such as Win32/Matsnu (which can subsequently drop Nitol and Nymaim), and the report supplies example indicators and describes the implications for detection and sandboxing strategies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
