Threat researchers reported that attackers increasingly used malicious Microsoft Excel add-in files with the .xll extension as an initial access vector, exploiting Excel's xlAutoOpen behavior to run code with a single user action. HP Wolf Security said the technique was being used to deliver malware including Dridex, Agent Tesla, Raccoon Stealer, and Formbook, and noted that some samples were built with the legitimate Excel-DNA framework while others were custom downloaders that decrypted embedded configuration data, resolved APIs dynamically, fetched payloads, and executed them. Researchers also observed underground promotion of XLL dropper builders, indicating the method was becoming commoditized.
Fortinet and SANS documented active spam operations using the format in the wild. One campaign used DHL and Amazon-themed lures to distribute a signed malicious XLL that downloaded csrsc.exe from dmequest[.]com, saved it as %PUBLIC%\srtherhaeth[.]eXe, and installed a Rust-based Buer Loader variant that communicated with shipmentofficedepot[.]com; the file was signed with a certificate assigned to HORUM, likely to reduce detection. Separately, SANS observed a Hancitor malspam wave using DocuSign-themed emails and Google feedproxy links that redirected victims through compromised sites to an XLL payload, which then retrieved an HTA file and a Hancitor executable from srand04rf[.]ru, followed by activity linked to Cobalt Strike and Ficker Stealer. Defenders were advised to block inbound XLL attachments, restrict add-ins to trusted signed files, or disable proprietary Excel add-ins where possible.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On 2021-07-08, a Hancitor malspam wave used DocuSign-themed phishing emails to deliver a malicious Excel XLL add-in instead of the campaign's usual Word document. Enabling the add-in triggered immediate execution and led to Hancitor infection activity.
The SANS ISC report states that since 2021-06-08, Hancitor malspam changed from using docs.google.com links to feedproxy.google.com URLs in its phishing workflow.
Fortinet's report says the analyzed Buer Loader sample matched the newer Rust-based variant previously highlighted by Proofpoint in May 2021. The sample used Rust crates including whoami and communicated with shipmentofficedepot[.]com.
HP Wolf Security reported that recent malware campaigns increasingly used malicious Microsoft Excel XLL add-ins as an initial infection vector. The research tied XLL delivery to malware families including Dridex, Agent Tesla, Raccoon Stealer, and Formbook, and described both Excel-DNA-based and custom-built XLL malware.
FortiGuard Labs observed a broad spam campaign using DHL and Amazon-themed lures to distribute a signed malicious Excel XLL attachment named "Detailed Invoice.xll." When opened, the XLL executed via xlAutoOpen, downloaded csrsc.exe from dmequest[.]com, saved it locally, and installed Buer Loader.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
threatresearch.ext.hp.com
Open sourcefortinet.com
Open sourceisc.sans.edu
Open sourceexcel-dna.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.