logo

Malicious Document Threat

ID: f215979c-36eb-5375-95c3-ec3667b5dab8

STIX ID: report--f215979c-36eb-5375-95c3-ec3667b5dab8

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents a recent campaign of weaponized Microsoft Office documents that employ highly obfuscated VBA macros and advanced anti-VM/anti-sandbox checks — including novel techniques such as validating the Office RecentFiles count and querying external IP ownership via a MaxMind API — to avoid automated analysis. When checks pass, the macros download and install payloads such as Win32/Matsnu (which can subsequently drop Nitol and Nymaim), and the report supplies example indicators and describes the implications for detection and sandboxing strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.