
A Hidden Macrosheet Reopens Emotet's Front Door
A freshly submitted Excel file carrying a hidden Excel4 macrosheet supplies the initial-access step long missing from Emotet-tagged loader activity. YARA and sandbox detections confirm the auto-executing macro and its concealment, but the file shows no dropped payload or callback, leaving the handoff to a separate Dridex-fingerprinted DLL unproven.
A spreadsheet flagged as trojan.abracadabra/emotet, submitted for scanning barely a day before this review and already caught by 42 of 75 engines, carries an Excel4 macro built to fire the moment the file opens — and the macro logic itself sits inside a sheet the workbook keeps hidden from anyone who opens it in Excel. Two named detections establish this precisely: the YARA rule `SUSP_Excel4Macro_AutoOpen matches the auto-executing macro trigger, and Microsoft_Excel_Hidden_Macrosheet catches…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read