Microsoft Warns Users of New Malware Attack via a Disguised Excel Attachment

The new campaign uses malicious macro functions in an Excel attachment to attack Windows PCs.

Advertisement
By Tasneem Akolawala | Updated: 25 June 2019 13:19 IST
Highlights
  • The new malware campaign kicks off with an email and an attachment
  • A malicious file is installed, delivering the FlawedAmmyyy malware
  • The malware campaign is targeted towards Korean users
Microsoft Warns Users of New Malware Attack via a Disguised Excel Attachment

Microsoft has warned users of a new malware campaign

Photo Credit: Twitter/ Microsoft Security Intelligence

Microsoft is drawing attention to a new malware attack that infects Windows systems using its own Office software's macro functions. A new malware campaign is doing the rounds and it essentially employs a complex infection chain to download and run the notorious FlawedAmmyy RAT malware directly in memory. The attack starts with an email and .xls attachment with content in the Korean language, indicating that it is primarily targeting Korean users. It uses malicious macro functions in an Excel attachment to attack Windows PCs.

According to security firm Proofpoint, the malicious campaign has been started by a group called TA505. They have been responsible for similar attacks in the past, the security firm says, and this particular latest trick involves a malicious email and an Excel attachment that Microsoft warns users from opening.

"When opened, the .xls file automatically runs a macro function that runs msiexec.exe, which in turn downloads an MSI archive. The MSI archive contains a digitally signed executable that is extracted and run[s], and that decrypts and runs another executable in memory," Microsoft notes in its series of tweets.

A file called wsus.exe is then downloaded and decrypted, and it is intelligently designed to pass off as the official Microsoft Windows Service Update Service (WSUS). It is digitally signed on June 19, and decrypts the payload in RAM, delivering the FlawedAmmyy payload.

Advertisement

Microsoft says that its Threat Protection defends customers from this attack. “Cloud-based machine learning protections in Microsoft Defender ATP blocked all of the components of this attack at first sight, including the FlawedAmmyy RAT payload. Office 365 ATP detects the email campaign,” the company notes.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Microsoft, FlawedAmmyy, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1. Microsoft Wants Websites to Have an AI-Powered Natural Language Interface
  2. iQOO Neo 10 Pro+ With Snapdragon 8 Elite, 6,800mAh Battery Launched
  3. Google I/O 2025: Here Are All the Major AI Announcements
  4. Google's New Beam Video Communication Platform Can Turn 2D Video Into 3D
  5. Nothing Phone 3 Confirmed to Launch Globally in July
  6. Apple WWDC 2025 Scheduled From June 9 to June 13: All You Need to Know
  7. Gemini 2.5 Series Gets Improved Capabilities and a Deep Think Mode
  1. HP OmniStudio X All-in-One PC With Intel Core Ultra 7 CPU Launched in India: Price, Specifications
  2. Android 16 Release: Everything You Can Expect from Google’s Upcoming OS Update
  3. Google I/O 2025: Everything Announced From Gemini 2.5, AI Mode to Project Astra
  4. Asus ExpertBook P3 Series With AMD Ryzen AI 7 350 Processor Launched at Computex 2025
  5. Tesla on Track to Launch Robotaxi Trial in Austin, Texas, by June End, Musk Says
  6. Stellar Blade Sequel Confirmed by Shift Up, Launch Planned Before 2027
  7. Epic Games' Fortnite Returns to Apple App Store in US After Nearly Five Years
  8. Amazon's Drones Can Now Deliver New Categories of Devices Like iPhone, AirPods and More
  9. Infinix GT 30 Pro Leaked Images Suggest RGB Lighting, Colour Options Ahead of Global Debut
  10. Bitcoin Surges Past $107,000 for First Time Since January as Altcoins Rally
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.