Threat Actors Abuse Red Team Tool MacroPack to Deliver Malware
ID: c2e0819f-f584-5ba6-aa06-777eab641f81
STIX ID: report--c2e0819f-f584-5ba6-aa06-777eab641f81
Feed Name: Security Boulevard
Threat Score
Talos researchers found threat actors abusing the legitimate MacroPack payload generator to produce malicious Microsoft Office documents that deliver post-exploitation frameworks (Havoc, Brute Ratel) and the PhantomCore RAT; multiple VBA-based lures were uploaded to VirusTotal from several countries, with C2 infrastructure ties and use of obfuscation techniques to hinder analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
