Excel macros can help you save time by doing repetitive tasks for you on your spreadsheets. These actions include types of data manipulation you do frequently when compiling reports. Unfortunately, however, malicious actors have also been using Excel macros as vectors for passing on malware. To fight this, earlier this year, Microsoft disabled Excel macros 4.0 by default but it looks like scammers are still able to target Excel users via macros, let’s dig into this a little more.
Researchers at cybersecurity specialists Netskope have released a report that outlines how Excel files are still being used for malicious reasons. They stated that they have discovered a lot of dangerous Excel documents that can target users of older and, therefore, unprotected versions of Microsoft Excel.
The infected macros they discovered are carrying a well-known trojan called Emotet, which is capable of stealing the victim’s information and then dropping further instances of malware onto the device.
Gustavo Palazolo, the lead researcher at Netskope, who published the report, had this to say on the extent of the vulnerability:
“we found 776 malicious spreadsheets submitted between June 9, 2022 and June 21, 2022, which abuse Excel 4.0 (XLM) macros to download and execute Emotet’s payload. Most of the files share the same URLs and some metadata. We extracted 18 URLs out of the 776 samples, four of which were online and delivering Emotet.”
Basically, this all means that scammers are sending out Excel spreadsheets that are infected with a trojan malware called Emotet that infects devices and networks it finds its way onto. This means that once again, we are talking about a phishing scam and the best way to defend against it, as well as ensuring you’re running the latest version of Excel, is to stop it from infecting your device in the first place.
Phishing scams try to catch you out with fake links. In this particular case, potential victims receive emails containing attachments like payment forms or other types of spreadsheet. This means that to stay alert to this scam you need to know how to spot phishing scams. To learn how to do so, check out our guide to spotting fake email scams.