Multiple security firms reported phishing campaigns that weaponized Microsoft PowerPoint Add-in files (.ppam) to deliver Agent Tesla and, in some variants, other malware such as Lokibot, AZORult, NanoCore RAT, and a cryptocurrency clipboard stealer. The lures commonly masqueraded as business documents such as wire transfer receipts or templates, then abused PowerPoint add-in behavior to trigger VBA execution when the file was closed. The macro chains launched living-off-the-land tools including mshta.exe, PowerShell, and Outlook COM automation, while shortened links and services such as Pastebin, Bitly, Blogspot, MediaFire, and GitHub hosted staged payloads and command infrastructure. Researchers linked several of the campaigns to Aggah, which targeted organizations across multiple countries and sectors and used spoofed business email domains to improve delivery.

Get the infrastructure and lures behind it.
12 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs analyzed a phishing campaign that used a fake purchase order and a malicious PPAM attachment named "order001.ppam" to target a Ukrainian manufacturing organization involved in raw materials and chemicals. The multistage chain used Bitly and MediaFire-hosted payloads, registry and scheduled-task persistence, and injected Agent Tesla into aspnet_compiler.exe.
Netskope Threat Labs observed an increase since December 2021 in phishing campaigns using malicious PowerPoint add-in files. The campaigns delivered AgentTesla and a PowerShell-based cryptocurrency clipboard stealer via cloud-hosted payload stages.
HP observed the intermediary wallet transfer the balance to Bitcoin address 1NDyJtNTjmwk5xPNhjgAMu4HDHigtobu1s. The destination address was associated with Binance.
The balance from the attacker Bitcoin wallet was transferred to intermediary wallet 1PGRpP14sSBER6x2choH31wkML1hXqykNj. This movement was part of HP's tracing of proceeds from the campaign's cryptocurrency theft.
HP reported that 0.00311321 Bitcoin was transferred into the attacker wallet used by the campaign, possibly from a victim. The wallet was tied to the campaign's clipboard-stealing component.
HP Wolf Security reported that in May 2020 an Aggah-linked malspam campaign used renamed PowerPoint add-ins to deliver Agent Tesla and a PowerShell Bitcoin clipboard stealer. Telemetry showed targeting across six sectors and eight countries, predominantly in Europe.
ThreatLabz observed malicious Microsoft PowerPoint files in the wild in March 2020 delivering AZORult and NanoCore RAT through a multistage loader chain. The activity targeted users in South Korea and Indonesia and was correlated to the Aggah campaign.
The .NET loader later named FreeDom was first observed on VirusTotal. Researchers described it as a GZip-compressed .NET loader used to inject final malware into notepad.exe.
ThreatLabz later referenced Unit 42 documentation from April 2019 that associated the Aggah campaign with large-scale activity using services such as Bitly, BlogSpot, and Pastebin for command-and-control and payload delivery.
SANS analyzed a malspam campaign delivering Agent Tesla through a macro-enabled PowerPoint add-in file named SKM-03753WIRE23560USD.ppam masquerading as a wire transfer receipt. The multistage chain used PowerShell, mshta, MediaFire, Blogger, GitHub, NSudo, and a .NET injector to disable defenses and inject Agent Tesla into aspnet_compiler.exe.
Trustwave analyzed a malicious spam campaign using a PowerPoint add-in attachment named "REQUEST FOR OFFER 08-20-2020.ppt." The Auto_Close-triggered chain used a crafted j.mp URL, Pastebin-hosted stages, AMSI bypass, and memory injection to deliver Lokibot.
Xavier Mertens analyzed a phishing-delivered PowerPoint add-in disguised as "Payments detail.pot" that silently installed and executed an Auto_Close macro on exit. The chain used j.mp and Pastebin-hosted stages to establish persistence, bypass AMSI, and deliver AgentTesla.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 165 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcefortinet.com
Open sourcenetskope.com
Open sourceisc.sans.edu
Open sourcetrustwave.com
Open sourcethreatresearch.ext.hp.com
Open sourceisc.sans.edu
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.