EXECUTIVE SUMMARY
Researchers have discovered a series of malicious Microsoft Office documents generated by the MacroPack framework were identified. These documents were uploaded from various countries, including China, Pakistan, Russia, and the U.S. MacroPack, originally designed for Red Team exercises, is now being utilized by threat actors to deploy various malicious payloads. The documents in question feature different lures and techniques but share common attributes linked to MacroPack.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have discovered a series of malicious Microsoft Office documents generated by the MacroPack framework were identified. These documents were uploaded from various countries, including China, Pakistan, Russia, and the U.S. MacroPack, originally designed for Red Team exercises, is now being utilized by threat actors to deploy various malicious payloads. The documents in question feature different lures and techniques but share common attributes linked to MacroPack.[emaillocker id="1283"]
The MacroPack framework generates VBA code with obfuscated elements to evade detection, including function and variable renaming, string encoding, and removal of comments. Discovered documents exhibit stages of execution before contacting command and control (C2) servers. Notably, documents from China and Pakistan delivered Havoc and Brute Ratel payloads, while Russian-origin documents utilized a variant of PhantomCore. These documents often include non-malicious VBA subroutines sourced from legitimate references, which may lower the suspicion level and help bypass anti-malware heuristics. Additionally, documents from the U.S. utilized a Markov Chain-based name generator to obfuscate their code further.
The use of MacroPack by malicious actors illustrates its potential for abuse beyond its intended Red Team applications. The documents analyzed demonstrate sophisticated evasion techniques and varied payloads, reflecting a broader trend of leveraging legitimate tools for malicious purposes. While no direct attribution to specific threat actors was possible, the patterns observed highlight the importance of vigilance against such threats. Organizations should ensure they are using updated Office versions and maintain robust detection capabilities to address evolving threats from tools like MacroPack.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1106 | Native API | |
| Persistence | T1543 | Create or Modify System Process |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Collection | T1074 | Data Staged |
| Command and Control | T1071 | Application Layer Protocol |
| T1219 | Remote Access Software | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/red-team-tool-macropack-abused-in-attacks-to-deploy-brute-ratel/