
Hidden Excel4 Macro Resurfaces, Drops Emotet Loader with Dridex-Linked JA3
A freshly submitted hidden-macrosheet spreadsheet reconfirms an old Excel4 auto-open trick, but this time it hands off to a Zenpak-labelled Emotet DLL with anti-debug and self-propagation behavior. The loader's network fingerprint ties to Dridex infrastructure even as its compile date lags three years behind deployment.
A hidden-macrosheet spreadsheet submitted just eight days before this analysis, on 2026-09-19 (f2f0b898…), reconfirms one of the oldest tricks still working in commodity malspam: burying an Excel4 auto-open macro inside a sheet the workbook itself keeps hidden from the user. What makes this snapshot notable isn't the delivery mechanism — that has been documented in this campaign before — but what it hands off to.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read