Threat actors are increasingly leveraging weaponized document formats and add-ins to compromise Windows users, with recent campaigns targeting organizations in multiple countries. One operation uncovered by researchers used phishing emails with RAR archives containing obfuscated JavaScript payloads, which exploited the CVE-2017-11882 vulnerability in Microsoft Office's Equation Editor. The infection chain included the use of malicious SVG files, ZIP archives with LNK shortcuts, and a sophisticated four-stage execution pipeline involving steganographically embedded .NET assemblies and the abuse of legitimate open-source libraries, all designed to evade detection and deliver commodity loaders for Remote Access Trojans and information stealers.
Separately, attackers have been abusing Microsoft Excel's XLL add-in format to deliver malware, with a notable increase in such activity since 2021. Recent incidents include the submission of malicious XLL files to VirusTotal from Ukraine and Russia, which contained a backdoor named EchoGather capable of system reconnaissance, command execution, and file transfer. These XLL-based attacks often use open-source frameworks like Excel-DNA to facilitate payload delivery and in-memory execution, further complicating detection and mitigation efforts for targeted organizations.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Based on standardized methods and class naming conventions, researchers concluded that the loader framework used in the email campaign appears to be shared among multiple threat actors rather than tied to a single group.
The campaign used a four-stage execution chain with obfuscation, steganography, process injection, and a novel UAC bypass to deploy malware including PureLog Stealer, Katz Stealer, DC Rat, Async Rat, and Remcos.
Researchers reported a separate email-based malware campaign targeting manufacturing and government organizations in Italy, Finland, and Saudi Arabia using weaponized Office documents, malicious SVG files, and ZIP archives containing LNK shortcuts.
The Intezer report also tied ruzede[.]com to a WinRAR path traversal and alternate data stream exploitation chain using CVE-2025-8088 to deliver a PowerShell downloader, aligning with previously observed Paper Werewolf tradecraft.
Infrastructure analysis connected the Paper Werewolf activity to the domains fast-eda[.]my and ruzede[.]com, as well as PowerShell-based loaders that displayed Russian-language decoy PDFs while running the backdoor.
The malicious XLL loader was designed to trigger from DllMain during DLL_THREAD_DETACH rather than standard XLL exports, then drop and execute a second-stage backdoor dubbed EchoGather, likely to evade sandbox and behavior-based detection.
In late October 2025, a campaign attributed to Paper Werewolf (also known as GOFFEE) used a malicious 64-bit Excel XLL loader to infect targets, primarily Russian organizations.
According to the report, use of Excel XLL add-ins expanded beyond advanced threat groups and became more common in commodity malware campaigns starting in 2021.
The Intezer report notes that APT10 had been abusing Excel XLL add-ins to execute arbitrary code since at least 2017, establishing an early precedent for this technique in targeted intrusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.