Microsoft may have blocked macros, but crooks are still finding a way

computing

(Image credit: Shutterstock.com / monticello)

Microsoft may have blocked macros from running by default in its Office suite of programs, but there are workarounds, researchers are saying. 

Several months after the ban was introduced, one specific workaround is seeing an uptick in adoption in the cybercriminal community, according to a new report from  Cisco Talos. 

The team claims cybercriminals are increasingly using XLL files (as opposed to XLS and XLSX) to deliver malicious code to target endpoints (opens in new tab).

Growing in popularity

XLL files are “a type of dynamic link library (DLL) file that can only be opened by Excel”, the researchers explain. In other words, with XLL files, Microsoft Excel spreadsheets can take advantage of additional functionality coming from third-party apps. 

While the weaponization of XLL files is nothing new (first samples have been reported as early as 2017, it was said), these files were rarely used until Microsoft decided to block the running of macros in files downloaded from the internet. Now, since 2021, more malware families started deploying the alternative solution. 

“For quite some time after [mid-2017], the usage of XLL files is only sporadic and it does not increase significantly until the end of 2021, when commodity malware families such as Dridex and Formbook started using it,” Vanja Svajcer, outreach researcher for Cisco Talos noted in the report.

“Currently a significant number of advanced persistent threat actors and commodity malware families are using XLLs as an infection vector and this number continues to grow.”

Read more

> Microsoft Excel has unveiled an absolutely mind-blowing new feature
> Microsoft has changed its mind about blocking Office macros by default
> These are the best firewalls right now (opens in new tab)

Among the groups using XLL files are the Chinese threat actor APT10 (AKA Potassium), which used it to distribute the Anel Backdoor. Then there is Cicada (AKA Stone Panda, TA410) a group that’s allegedly “loosely tied” to APT10, as well as DoNot, and Fin7.

Apparently, the threat actors have been using XLL files to deliver various malware families, such as Warzone RAT, or Ducktail. Businesses are warned to expect an increasing number of such threats going forward.

    Via: The Register (opens in new tab)

    Are you a pro? Subscribe to our newsletter

    Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    By submitting your information you agree to the Terms & Conditions (opens in new tab) and Privacy Policy (opens in new tab) and are aged 16 or over.

    Sead Fadilpašić

    Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

    TECH NEWS RELATED

    9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    Watching movies online can be a hassle; Especially when there is a lot of buffering. This is one of the biggest reasons for people to download their movies and watch them offline. However, I found this specific query in a forum where people were asking to recover a downloaded movie ...

    View more: 9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    How To Snip Screen On Your Laptop?

    Taking a screenshot is not a complicated process. All of us are familiar with at least one way to do it. However, there are several ways to capture your screen for a frame. We made this article to show you all the different ways you can grab your screens. If ...

    View more: How To Snip Screen On Your Laptop?

    How To Connect AirPods To A Laptop?

    The Apple AirPods are, undoubtedly, some of the best earpieces available on the electronics market. With three generations of different AirPods models, these sleek, ivory earphones are quite popular. Apart from the appearance and quality, AirPods are known for being versatile. Irrespective of what the host device is, AirPods can ...

    View more: How To Connect AirPods To A Laptop?

    7 Best Ways To Fix DistributedCOM Error In Windows

    If you open the Event Viewer utility often, you may notice a DistributedCOM Error on Windows. Let’s know what this DistributedCOM Error Windows error is, how it’s caused, and how you can fix it. Contents show 1 What Is the DistributedCOM Error Windows 10 and 11? 2 What is the ...

    View more: 7 Best Ways To Fix DistributedCOM Error In Windows

    12 Easy Fixes For Webcam Not Working In Windows

    Cameras are becoming quite common for PCs. We use meetings on Zoom, Microsoft Teams, Skype, and other options. The operating system might not be at fault if your camera isn’t working. You can use the given solutions to solve the Webcam Not Working Windows issue quickly. We have covered ...

    View more: 12 Easy Fixes For Webcam Not Working In Windows

    Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Is  Windows 10 Sound Not Working on your PC? This is a common issue faced by many Windows users.  If you are one among them, you are in the right place. This article gives you 11 solutions to fix the no-sound issues in Windows 10.  Contents show 1 Reasons For ...

    View more: Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Fix CAA20004 Microsoft Teams Sign in Error

    Microsoft Teams have a bundle of excellent and attractive features that provides you with easy communication among friends, even classes and offices were conducted online. There’s a lot going on in MS Teams, for example, you can chat via messages and video calls, and at the same time share files ...

    View more: Fix CAA20004 Microsoft Teams Sign in Error

    How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows standalone updates packages are useful when your Windows updater is not working or you want to install a certain update manually. However, running these updated packages, sometimes, shows the error message “This update is not applicable to your computer” or “This update is not applicable to your computer”. ...

    View more: How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows Dual Boot Menu Not Showing: 6 Easy Ways To Fix

    12 Best Fixes: Windows 10 Start Menu Search Not Working

    How to customize and publish a Microsoft Bookings page?

    Chic-Fil-A’s Training Program Apparently Features a Familiar Fallout Face

    Microsoft Teams Status not updating or changing

    Don’t Buy a Foldable Until Samsung Brings This Prototype to Life

    Windows Encryption Not Working? 6 Best Ways To Fix

    How to get Apple Calendar on Windows PC

    Windows Update Error 0x80073701: 9 Best Ways To Fix

    Best Ways To Fix Slow Internet During VPN On Windows 11

    6 Solutions To Fix Wmpnetwk High CPU Usage In Windows

    Save Time in Microsoft PowerPoint by Making Your Own Theme

    OTHER TECH NEWS

    Top Car News Car News