Microsoft Warns Users of New Malware Attack via a Disguised Excel Attachment

The new campaign uses malicious macro functions in an Excel attachment to attack Windows PCs.

Advertisement
By Tasneem Akolawala | Updated: 25 June 2019 13:19 IST
Highlights
  • The new malware campaign kicks off with an email and an attachment
  • A malicious file is installed, delivering the FlawedAmmyyy malware
  • The malware campaign is targeted towards Korean users

Microsoft has warned users of a new malware campaign

Photo Credit: Twitter/ Microsoft Security Intelligence

Microsoft is drawing attention to a new malware attack that infects Windows systems using its own Office software's macro functions. A new malware campaign is doing the rounds and it essentially employs a complex infection chain to download and run the notorious FlawedAmmyy RAT malware directly in memory. The attack starts with an email and .xls attachment with content in the Korean language, indicating that it is primarily targeting Korean users. It uses malicious macro functions in an Excel attachment to attack Windows PCs.

According to security firm Proofpoint, the malicious campaign has been started by a group called TA505. They have been responsible for similar attacks in the past, the security firm says, and this particular latest trick involves a malicious email and an Excel attachment that Microsoft warns users from opening.

Advertisement

"When opened, the .xls file automatically runs a macro function that runs msiexec.exe, which in turn downloads an MSI archive. The MSI archive contains a digitally signed executable that is extracted and run[s], and that decrypts and runs another executable in memory," Microsoft notes in its series of tweets.

A file called wsus.exe is then downloaded and decrypted, and it is intelligently designed to pass off as the official Microsoft Windows Service Update Service (WSUS). It is digitally signed on June 19, and decrypts the payload in RAM, delivering the FlawedAmmyy payload.

Advertisement

Microsoft says that its Threat Protection defends customers from this attack. “Cloud-based machine learning protections in Microsoft Defender ATP blocked all of the components of this attack at first sight, including the FlawedAmmyy RAT payload. Office 365 ATP detects the email campaign,” the company notes.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, FlawedAmmyy, Windows
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Nord 6 India Launch Today: What We Know So Far
  2. Vivo X300 FE Launch Timeline Leaked Alongside These Three Colourways
  3. Fujifilm Launches XT-30 III Mirrorless Camera in India at This Price
  4. Asus TUF Gaming A14 (2026) Review: No Longer Just for Gamers
  5. Lenovo Launches New IdeaPad 5 2-in-1 and Yoga Series Laptops in India
  6. Redmi Note 15 SE 5G With 5,800mAh Battery Goes on Sale in India: See Offers
  7. Google, OpenAI to Join Forces to Fight AI Model Copying in China
  8. iPhone Fold Dummy Unit Leak Gives Us Another Look at Apple's Wide Foldable
  9. Nothing Phone 3a Lite to Get More Expensive in India Soon, Tipster Claims
  10. Artemis II Completes Historic Lunar Flyby, Sets New Spaceflight Record
  1. Solana Foundation Launches STRIDE Network to Strengthen DeFi Security
  2. Realme C100 5G Launched With 50-Megapixel Rear Camera and 7,000mAh Battery: Price, Specifications
  3. Fujifilm XT-30 III Mirrorless Digital Camera Launched in India With X-Trans CMOS 4 Sensor: Price, Features
  4. Xiaomi’s Next Foldable Might Not Launch as Early as Expected, Tipster Claims
  5. Infinix Note 60 Pro Confirmed to Launch With Same Snapdragon Chipset Available on Global Model
  6. iPhone Fold Dummy Unit Leak Offers Another Look at Apple's Wide Foldable Along With iPhone 18 Pro Models
  7. Anthropic, Google and OpenAI Join Hands to Fight AI Model Copying Attempts by Chinese Rivals: Report
  8. Repu Udayam 10 Gantalaku Now Available on Prime Video: What You Need to Know
  9. IT Department Reportedly Issues Tax Notices to Crypto Traders Over Past Unreported Transactions
  10. Realme Buds T500 Pro India Launch Date Revealed, Colour Options, Key Features Revealed
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.