APTMembers
APT

Hidden Excel4 Macro Resurfaces, Drops Emotet Loader with Dridex-Linked JA3

A freshly submitted hidden-macrosheet spreadsheet reconfirms an old Excel4 auto-open trick, but this time it hands off to a Zenpak-labelled Emotet DLL with anti-debug and self-propagation behavior. The loader's network fingerprint ties to Dridex infrastructure even as its compile date lags three years behind deployment.

Sep 27, 2026, 22:41 (UTC+9)Last seenSep 27, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC15RegionsUS

A hidden-macrosheet spreadsheet submitted just eight days before this analysis, on 2026-09-19 (f2f0b898…), reconfirms one of the oldest tricks still working in commodity malspam: burying an Excel4 auto-open macro inside a sheet the workbook itself keeps hidden from the user. What makes this snapshot notable isn't the delivery mechanism — that has been documented in this campaign before — but what it hands off to.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence