EN AR RU ZH FR ES

March 08, 2025 • By

Live Phishing Attack Delivers Malware Using a Novel Infection Technique

A phishing campaign using Word documents that download password-protected Excel files to construct malicious macros, bypassing security filters by building the payload dynamically on the victim's system.

Key Takeaways

  • Phishing emails deliver Word documents that, when macros are enabled, download password-protected Excel files.
  • The Word document reads Excel cell contents and converts them into VBA macro functions to evade detection.
  • Registry policies are modified to disable Excel macro warnings before executing the malicious payload.
  • Zloader malware is downloaded and executed using rundll32.exe after the macro construction completes.
  • Breaking the infection chain requires training users never to enable macros in Office documents from untrusted sources.

McAfee researchers warn that a recent phishing campaign is delivering malware via non-malicious Word documents. When a user opens the document and enables content, it downloads an Excel file that is used to construct a malicious macro once the document is on the system. This enables macros to evade security filters.

“The malware is delivered via a phishing email that contains an attachment of a Microsoft Word document,” the researchers write. “Upon opening the document and enabling macros, the Word document downloads and opens another password-protected Microsoft Excel document.

After downloading the XLS file, Word VBA reads the contents of the cells in the XLS file, creates a new macro for the same XLS file, and writes the contents of the cells to XLS VBA macros as functions. Once the macros are written and prepared, the Word document changes the registry policy to Disable Excel Macro Warning and invokes the malicious macro function contained in the Excel file. The Excel file downloads the Zloader payload at this point. Rundll32[dot]exe is then used to execute the Zloader payload.”

Notably, the user must still enable macros in the first document in order to download the second. As a result, if users are trained to never enable macros in an Office document, the infection chain can be broken.

“Malicious documents have served as an entry point for the majority of malware families, and these attacks have evolved their infection techniques and obfuscation, moving away from direct payload downloads from VBA and toward dynamic payload downloads, as discussed in this blog,” the researchers write.

“The use of such agents in the infection chain is not limited to Word or Excel; additional threats may download their payloads using other off-the-land tools.

Macros are disabled by default in Microsoft Office applications due to security concerns. We suggest that you enable them only when you receive a document from a trusted source.”

Security awareness training in the modern era teaches employees to adhere to security best practices.

Frequently Asked Questions

A phishing email contains a Word document that downloads a password-protected Excel file. When macros are enabled in Word, it reads the Excel cells and converts them into VBA macros, then disables Excel macro warnings and executes the malicious payload.
The malware is constructed dynamically on the victim's system rather than downloaded directly, allowing it to bypass traditional malware detection that looks for direct payload downloads from VBA code.
The Zloader malware is downloaded by the constructed Excel macro and executed using rundll32.exe.
No. The infection chain requires the user to enable macros in the initial Word document. If users are trained never to enable macros in untrusted documents, the attack cannot proceed.
Security awareness training that teaches employees never to enable macros in Office documents unless they come from a trusted source, combined with keeping macros disabled by default.

Company Profile

Refer & Earn

Every website needs reliable hosting.

Fast, secure, locally-managed web hosting in Kuwait — daily backups, KNET-ready and supported in Arabic & English. Pick a plan and go live with confidence.