C&CMembers
C&C

A Hidden Macrosheet Reopens Emotet's Front Door

A freshly submitted Excel file carrying a hidden Excel4 macrosheet supplies the initial-access step long missing from Emotet-tagged loader activity. YARA and sandbox detections confirm the auto-executing macro and its concealment, but the file shows no dropped payload or callback, leaving the handoff to a separate Dridex-fingerprinted DLL unproven.

Sep 20, 2026, 14:37 (UTC+9)Last seenSep 20, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC15RegionsUS

A spreadsheet flagged as trojan.abracadabra/emotet, submitted for scanning barely a day before this review and already caught by 42 of 75 engines, carries an Excel4 macro built to fire the moment the file opens — and the macro logic itself sits inside a sheet the workbook keeps hidden from anyone who opens it in Excel. Two named detections establish this precisely: the YARA rule `SUSP_Excel4Macro_AutoOpen matches the auto-executing macro trigger, and Microsoft_Excel_Hidden_Macrosheet catches…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence