logo

Threat Actors Abuse Red Team Tool MacroPack to Deliver Malware

ID: c2e0819f-f584-5ba6-aa06-777eab641f81

STIX ID: report--c2e0819f-f584-5ba6-aa06-777eab641f81

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2024-09-06

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Talos researchers found threat actors abusing the legitimate MacroPack payload generator to produce malicious Microsoft Office documents that deliver post-exploitation frameworks (Havoc, Brute Ratel) and the PhantomCore RAT; multiple VBA-based lures were uploaded to VirusTotal from several countries, with C2 infrastructure ties and use of obfuscation techniques to hinder analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.