πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 08 Mar 2023 08:23:21 GMT
βββββββββββββββ
βοΈTitle: Letβs Defend WriteupβββExcel 4.0 Macros
βββββββββββββββ
πLink: https://medium.com/p/6fa4b037afe7
βββββββββββββββ
Tags: #macro #excel #malware_analysis #lets_defend #writeup
βββββββββββββββ
πDate: Wed, 08 Mar 2023 08:23:21 GMT
βββββββββββββββ
βοΈTitle: Letβs Defend WriteupβββExcel 4.0 Macros
βββββββββββββββ
πLink: https://medium.com/p/6fa4b037afe7
βββββββββββββββ
Tags: #macro #excel #malware_analysis #lets_defend #writeup
Medium
Letβs Defend Writeup β Excel 4.0 Macros
Description: One of the employees has received a suspicious document attached in the email. When the e-mail flow is examined, it is seenβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Fri, 11 Aug 2023 15:53:22 GMT
βββββββββββββββ
βοΈTitle: How a Hacker can get access to your computer
βββββββββββββββ
πLink: https://medium.com/p/3090ed05a2d3
βββββββββββββββ
Tags: #macro #hacking #linux #vmware #caldera
βββββββββββββββ
πDate: Fri, 11 Aug 2023 15:53:22 GMT
βββββββββββββββ
βοΈTitle: How a Hacker can get access to your computer
βββββββββββββββ
πLink: https://medium.com/p/3090ed05a2d3
βββββββββββββββ
Tags: #macro #hacking #linux #vmware #caldera
Medium
How a Hacker can get access to your computer
Hello There,
πNew WriteupβοΈ
βββββββββββββββ
πDate: Tue, 29 Aug 2023 07:45:32 GMT
βββββββββββββββ
βοΈTitle: Initial access using a Malicious Document(MalDoc)
βββββββββββββββ
πLink: https://medium.com/p/e2901a50f89d
βββββββββββββββ
Tags: #red_team #cybersecurity #macro #initial_access
βββββββββββββββ
πDate: Tue, 29 Aug 2023 07:45:32 GMT
βββββββββββββββ
βοΈTitle: Initial access using a Malicious Document(MalDoc)
βββββββββββββββ
πLink: https://medium.com/p/e2901a50f89d
βββββββββββββββ
Tags: #red_team #cybersecurity #macro #initial_access
Medium
Initial access using a Malicious Document(MalDoc)
First, we will create a document containing an embedded macro. When the document is opened, the macro will automatically execute, initiating the download of a malicious Meterpreter payload andβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Thu, 14 Sep 2023 10:47:21 GMT
βββββββββββββββ
βοΈTitle: A Basic Static Analysis example- Analyzing malicious document with CyberChef
βββββββββββββββ
πLink: https://medium.com/p/d7b51f484d73
βββββββββββββββ
Tags: #cybersecurity #base64 #macro #cyberchef
βββββββββββββββ
πDate: Thu, 14 Sep 2023 10:47:21 GMT
βββββββββββββββ
βοΈTitle: A Basic Static Analysis example- Analyzing malicious document with CyberChef
βββββββββββββββ
πLink: https://medium.com/p/d7b51f484d73
βββββββββββββββ
Tags: #cybersecurity #base64 #macro #cyberchef
Medium
A Basic Static Analysis example- Analyzing malicious document with CyberChef
Hello everyone ,after my last posts about how hackers can get control of victimβs computer using a word document with malicious macro codeβ¦
β€· Title: Advent of Cyber 2024(THM) - Day 10βββPhishing
ββββββββββββββββββββββββ
πͺ Author: Moataz Osama
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 02 Jan 2025 14:06:55 GMT
ββββββββββββββββββββββββ
β Tags: #metasploit #macro #red_team #phishing #tryhackme
ββββββββββββββββββββββββ
πͺ Author: Moataz Osama
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 02 Jan 2025 14:06:55 GMT
ββββββββββββββββββββββββ
β Tags: #metasploit #macro #red_team #phishing #tryhackme
Medium
Advent of Cyber 2024(THM) - Day 10 β Phishing
Mayor Malware had one, just one SOC-mas wish:
β€· Title: Macro SonrasΔ± DΓΆneme Uyum SaΔlayan Tehdit AktΓΆrlerin YΓΆntemleri
ββββββββββββββββββββββββ
πͺ Author: Mehmet Kadir CIRIK
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Jan 2025 10:50:19 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #ransomware #malware #macro #apt
ββββββββββββββββββββββββ
πͺ Author: Mehmet Kadir CIRIK
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 06 Jan 2025 10:50:19 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #ransomware #malware #macro #apt
Medium
Macro SonrasΔ± DΓΆneme Uyum SaΔlayan Tehdit AktΓΆrlerin YΓΆntemleri
β€· Title: OSCP Tactics: How to Create a Malicious Word Macro for Remote Code Execution
ββββββββββββββββββββββββ
πͺ Author: enigma_
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 25 Feb 2025 00:34:06 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #macro #rce #ethical_hacking #oscp
ββββββββββββββββββββββββ
πͺ Author: enigma_
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 25 Feb 2025 00:34:06 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #macro #rce #ethical_hacking #oscp
Medium
OSCP Tactics: How to Create a Malicious Word Macro for Remote Code Execution
Donβt click that βEnable Contentβ buttonβ¦
β€· Title: Why Use a Macro Pad?
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 04 Jun 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #General InfoSec Tips & Tricks #How_To #Informational #Mitchell Stein #Elgato #Macro pad #Stream deck
ββββββββββββββββββββββββ
πͺ Author: BHIS
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 04 Jun 2025 14:00:00 +0000
ββββββββββββββββββββββββ
β Tags: #General InfoSec Tips & Tricks #How_To #Informational #Mitchell Stein #Elgato #Macro pad #Stream deck
Black Hills Information Security, Inc.
Why Use a Macro Pad? - Black Hills Information Security, Inc.
Compression is everywhereβin files, videos, storage, and networksβso itβs only natural it should also be in your workflow too. You can βcompressβ a series of tedious, repetitive tasks requiring multiple steps and several configurations into a single buttonβ¦
β€· Title: THM Industrial Intrusion CTF Task 14 Backdoored Bus
ββββββββββββββββββββββββ
πͺ Author: Not wrench
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 02 Jul 2025 06:04:38 GMT
ββββββββββββββββββββββββ
β Tags: #macro #security #forensics #ctf #tryhackme
ββββββββββββββββββββββββ
πͺ Author: Not wrench
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 02 Jul 2025 06:04:38 GMT
ββββββββββββββββββββββββ
β Tags: #macro #security #forensics #ctf #tryhackme
Medium
THM Industrial Intrusion CTF Task 14 Backdoored Bus π
File : Docker_split
β€· Title: LetsDefend :
SOC205βββMalicious Macro has been executed
ββββββββββββββββββββββββ
πͺ Author: 4th3n4x
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Oct 2025 11:45:03 GMT
ββββββββββββββββββββββββ
β Tags: #macro #cybersecurity #lets_defend #malware #c2
SOC205βββMalicious Macro has been executed
ββββββββββββββββββββββββ
πͺ Author: 4th3n4x
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Oct 2025 11:45:03 GMT
ββββββββββββββββββββββββ
β Tags: #macro #cybersecurity #lets_defend #malware #c2
Medium
LetsDefend :
SOC205βββMalicious Macro has been executed
SOC205βββMalicious Macro has been executed
Trigger Reason : Suspicious file detected on system.
β€· Title: Bitter APT Attacks China/Pakistan with WinRAR Zero-Day and New C# Backdoor via Office Macro
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 22 Oct 2025 00:11:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Bitter APT #C# Backdoor #china #cyber_espionage #Macro Attack #Pakistan #WinRAR Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 22 Oct 2025 00:11:32 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Bitter APT #C# Backdoor #china #cyber_espionage #Macro Attack #Pakistan #WinRAR Vulnerability
Daily CyberSecurity
Bitter APT Attacks China/Pakistan with WinRAR Zero-Day and New C# Backdoor via Office Macro
Qianxin exposed Bitter APT using a WinRAR path traversal flaw and malicious Office macros to deploy a C# backdoor against military/FinTech targets in Asia. The attack sets up scheduled persistence.
β€· Title: Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 23 Oct 2025 00:20:34 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 23 Oct 2025 00:20:34 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #Credential Stealing #cyber_espionage #FakeUpdate #Iran APT #Macro Malware #MuddyWater #NordVPN #Phoenix Backdoor
Daily CyberSecurity
Iran-Linked MuddyWater Deploys Phoenix v4 Backdoor via Compromised Emails and NordVPN Exit Node
Group-IB exposed MuddyWater using NordVPN to send phishing emails that deliver the Phoenix v4 backdoor. The malware steals credentials via a custom Chromium stealer disguised as a calculator.
β€· Title: Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Nov 2025 00:06:50 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Nov 2025 00:06:50 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
Daily CyberSecurity
Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
ENKI exposed a Lazarus Group espionage campaign targeting aerospace/defense firms. The new Comebacker variant uses malicious Word macros and ChaCha20/AES to deliver a memory-resident backdoor.
β€· Title: Hiding in Plain Sight: APT28βs βOperation MacroMazeβ Hits European Govs
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Feb 2026 00:32:54 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #cyber_espionage #Fancy Bear #Forest Blizzard #Lab52 #living_off_the_land #Macro Malware #Operation MacroMaze #Spanish Government #Webhook.site
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 17 Feb 2026 00:32:54 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #APT28 #cyber_espionage #Fancy Bear #Forest Blizzard #Lab52 #living_off_the_land #Macro Malware #Operation MacroMaze #Spanish Government #Webhook.site
Daily CyberSecurity
Hiding in Plain Sight: APT28's "Operation MacroMaze" Hits European Govs
APT28's "Operation MacroMaze" targets Europe using Spanish gov decoys. The campaign uses "low-tech" macros & Webhook.site to evade detection.
β€· Title: Stealth & Persistence: MuddyWaterβs New Rust-Based Payload Mimics Cloudflare and Reddit
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 25 Feb 2026 00:06:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #Genians Report #infosec #Macro_based Attacks #MuddyWater APT #Operation Olalampo #RMM tool abuse #Rust malware #State_Sponsored Espionage #threat intelligence
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 25 Feb 2026 00:06:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Malware #Genians Report #infosec #Macro_based Attacks #MuddyWater APT #Operation Olalampo #RMM tool abuse #Rust malware #State_Sponsored Espionage #threat intelligence
Daily CyberSecurity
Stealth & Persistence: MuddyWaterβs New Rust-Based Payload Mimics Cloudflare and Reddit
Genians report reveals MuddyWater APT's shift to Rust-based malware and RMM tool abuse for long-term espionage across government and critical infrastructure.