Malicious Excel spreadsheets distributed in ZIP archives were used to infect Windows systems with malware assessed as likely SystemBC, using a GlobalSign-themed lure to convince users to enable macros. Once executed, the macro downloaded a Windows payload, wrote it to a newly created path under C:\, and established persistence through a scheduled task. The infected host then communicated with 109.234.39.169 over TCP port 4001, consistent with the observed SystemBC-related activity.
Follow-on intrusion activity included HTTP requests that returned obfuscated code used to launch Cobalt Strike, followed by HTTPS and DNS beaconing tied to fastonent[.]com and 192.169.6.8. The observed post-compromise behavior differed by environment: in an Active Directory lab, the infection progressed to Cobalt Strike activity, while a stand-alone host showed only the suspected SystemBC communications, indicating the malware chain may selectively deploy additional tooling on domain-connected systems.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
By the next day, several related samples had appeared in VirusTotal, indicating broader distribution of the same malicious Excel campaign. The campaign involved ZIP archives containing malicious spreadsheets likely sent as email attachments.
A malicious Excel spreadsheet using a GlobalSign-themed lure was uploaded to the Hatching Triage sandbox. The sample contained a macro that, when enabled, downloaded a malware payload later assessed by the author as likely SystemBC.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 96 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.