logo

Hackers Use MS Excel Macro to Launch Multi-Stage Malware Attack in Ukraine

ID: 86e01eac-8c23-5694-9e88-90b6a143f2dc

STIX ID: report--86e01eac-8c23-5694-9e88-90b6a143f2dc

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A multi-stage malware campaign targeting endpoints in Ukraine uses a malicious Excel document with an embedded VBA macro to deploy a HEX-encoded DLL downloader via regsvr32. The downloader performs geo-location checks (restricting further payload download to Ukrainian devices), checks for security tooling (e.g., Avast, Process Hacker) to abort if detected, and launches chained DLLs culminating in a Cobalt Strike Beacon that communicates with a C2 server (simonandschuster.shop); the attack employs obfuscation, self-deletion, injector delays, and parent-process termination to evade analysis and sandboxing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.