By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malware
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malware
Computing

Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malware

News Room
Last updated: 2025/02/25 at 12:52 PM
News Room Published 25 February 2025
Share
SHARE

Feb 25, 2025Ravie LakshmananMalware / Cyber Espionage

Opposition activists in Belarus as well as Ukrainian military and government organizations are the target of a new campaign that employs malware-laced Microsoft Excel documents as lures to deliver a new variant of PicassoLoader.

The threat cluster has been assessed to be an extension of a long-running campaign mounted by a Belarus-aligned threat actor dubbed Ghostwriter (aka Moonscape, TA445, UAC-0057, and UNC1151) since 2016. It’s known to align with Russian security interests and promote narratives critical of NATO.

Cybersecurity

“The campaign has been in preparation since July-August 2024 and entered the active phase in November-December 2024,” SentinelOne researcher Tom Hegel said in a technical report shared with The Hacker News. “Recent malware samples and command-and-control (C2) infrastructure activity indicate that the operation remains active in recent days.”

The starting point of the attack chain analyzed by the cybersecurity company is a Google Drive shared document that originated from an account named Vladimir Nikiforech and hosted a RAR archive.

The RAT file includes a malicious Excel workbook, which, when opened, triggers the execution of an obfuscated macro when prospective victims enable macros to be run. The macro proceeds to write a DLL file that ultimately paves the way for a simplified version of PicassoLoader.

In the next phase, a decoy Excel file is displayed to the victim, while, in the background, additional payloads are downloaded onto the system. As recently as June 2024, this approach was used to deliver the Cobalt Strike post-exploitation framework.

SentinelOne said it also discovered other weaponized Excel documents bearing Ukraine-themed lures to retrieve an unknown second-stage malware from a remote URL (“sciencealert[.]shop”) in the form of a seemingly harmless JPG image, a technique known as steganography. The URLs are no longer available.

Cybersecurity

In another instance, the booby-trapped Excel document is used to deliver a DLL named LibCMD, which is designed to run cmd.exe and connect to stdin/stdout. It’s directly loaded into memory as a .NET assembly and executed.

“Throughout 2024, Ghostwriter has repeatedly used a combination of Excel workbooks containing Macropack-obfuscated VBA macros and dropped embedded .NET downloaders obfuscated with ConfuserEx,” Hegel said.

“While Belarus doesn’t actively participate in military campaigns in the war in Ukraine, cyber threat actors associated with it appear to have no reservation about conducting cyber espionage operations against Ukrainian targets.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Kylie Jenner ‘wants to go to Oscars’ with Timothee Chalamet but may not attend
Next Article How Factory is Turning Ai Into ‘A Junior Developer in a Box’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Oracle looks to open up data access in the era of AI – News
News
This Refurbished Lenovo Chromebook Costs Less Than $100, While Supplies Last
News
From ‘Black Bag’ to ‘Nonnas,’ 10 movies you need to stream right now
Software
How to unblock ePorner for free
News

You Might also Like

Computing

Nvidia’s tailored-for-China H20 AI chip now available for pre-orders · TechNode

4 Min Read
Computing

Alibaba mulls sale of grocery retail chain Freshippo: report · TechNode

1 Min Read
Computing

China’s Chery reportedly forms standalone business unit in collaboration with Huawei · TechNode

1 Min Read
Computing

Xiaomi 15 smartphone set to debut with Snapdragon 8 Gen 4 in October · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?