Skip to main content
F.A.Q.

Emotet Rampant: Make sure to patch office for macro protection!

  • May 27, 2022
  • 4 replies
  • 178 views
Emotet Rampant: Make sure to patch office for macro protection!
TylerM
Administrator
Forum|alt.badge.img+25
  • Sr. Security Analyst & Community Manager

An increase in attacks by Emotet has been observed. Emotet uses Excel 4.0 macros to execute payloads on systems running Microsoft Office to gain access, steal data and perform other malicious acts.

These attacks usually appear in the form of an email with an attachment asking the user to open the file and take further action. Emotet is part of an attack chain that can lead to compromised credentials, exfiltrated data and ransomware attacks. 

This is the most common infection vector for Ransomware

The latest patches ensure that Excel 4.0 macros are disabled by default.

 

Please see more info here from Microsoft and CISA on our FAQ

4 replies

MajorHavoc
Bronze VIP
Forum|alt.badge.img+25
  • Bronze VIP
  • May 27, 2022

It was not clear. Does tis run on both Mac and Windows, or only effecting Windows machines? 


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • May 28, 2022

This dam bug is still around and causing Havoc! Right @MajorHavoc  😋

 

 


ProTruckDriver
Moderator

This dam bug is still around and causing Havoc! Right @MajorHavoc  😋

 

 

 


TylerM
Administrator
Forum|alt.badge.img+25
  • Author
  • Sr. Security Analyst & Community Manager
  • May 31, 2022

@MajorHavoc Windows as the macros typically invoke powershell which isn’t on Mac