Excel Files That Hack You Silently: A Shocking New XWorm v72 Phishing Campaign Is Spreading Fast

Listen to this Post

Featured Image

Introduction: A Quiet Excel File With Loud Consequences

A newly observed phishing campaign is once again proving that some of the most dangerous cyberattacks arrive disguised as everyday office documents. Security researchers are tracking a fresh wave of XWorm v7.2 infections delivered through malicious Excel add-in files, abusing a long-known Microsoft Office vulnerability to quietly establish deep, fileless control over infected systems. What looks like a harmless spreadsheet attachment is, in reality, a multi-purpose cyber weapon capable of ransomware deployment, distributed denial-of-service attacks, and encrypted command-and-control operations that are extremely difficult to detect.

Background: How the Campaign Came to Light

The activity was first highlighted in a threat intelligence update shared by Cybersecurity News Everyday via its @TweetThreatNews channel. The report referenced ongoing analysis published by independent researcher Hendry Adrian, noting a coordinated phishing effort distributing Excel .XLAM add-in files. These attachments exploit CVE-2018-0802, a vulnerability that many organizations mistakenly consider obsolete or irrelevant due to its age.

The Delivery Method: Phishing Emails With a Twist

Unlike traditional phishing emails that rely on macros embedded in standard .XLS or .XLSM files, this campaign leverages Excel add-ins. .XLAM files are less commonly scrutinized by users and, in some environments, may bypass stricter macro warnings. Once opened, the malicious add-in executes embedded code that exploits the vulnerability to move execution outside Excel’s usual sandbox.

Exploiting CVE-2018-0802: Old Bug, New Damage

CVE-2018-0802 is a memory corruption vulnerability in Microsoft Office that allows arbitrary code execution. While patches have been available for years, attackers continue to rely on it because of inconsistent patching practices across enterprises. In this campaign, exploitation does not immediately drop a traditional executable, reducing the likelihood of detection by signature-based antivirus tools.

Living Off the Land: Msbuild.exe Abuse

A critical stage of the attack involves the abuse of Msbuild.exe, a legitimate Microsoft build engine normally used by developers. By leveraging this trusted binary, the attackers deploy a fileless .NET module directly into memory. This “living off the land” technique allows malicious activity to blend seamlessly with legitimate system operations, complicating forensic analysis and incident response.

The Payload: XWorm v7.2 in Memory

Once executed, the in-memory payload reveals itself as XWorm v7.2, a modular remote access trojan. Operating without writing files to disk, the malware establishes persistence through stealthy mechanisms and immediately initiates encrypted communication with its command-and-control infrastructure.

Encrypted Command and Control Channels

The malware uses AES encryption to secure its C2 traffic, preventing network monitoring tools from easily inspecting command content. This encrypted channel allows attackers to issue real-time instructions, update modules, and exfiltrate data without exposing readable indicators on the wire.

Multi-Role Malware: More Than Just Espionage

XWorm v7.2 is not limited to surveillance. The same implant supports:

Ransomware deployment, allowing attackers to pivot from espionage to monetization.

DDoS functionality, enabling infected systems to participate in coordinated attacks.

Remote administration, granting full control over compromised machines.

This flexibility makes the campaign attractive to both financially motivated cybercriminals and access brokers supplying footholds to other threat actors.

Target Surface: Why This Attack Scales Easily

The campaign’s success lies in its simplicity. Excel attachments remain one of the most trusted file formats in corporate environments. Combined with an older vulnerability and legitimate Windows binaries, the attack chain requires minimal custom tooling while achieving high impact.

Detection Challenges for Defenders

Traditional endpoint detection solutions often struggle with fileless malware, especially when execution is handled by trusted binaries like Msbuild.exe. Without behavioral monitoring or memory analysis, many infections may go unnoticed until secondary actions—such as ransomware deployment—occur.

What Undercode Says:

A Case Study in Why “Patched Years Ago” Is a Dangerous Assumption

This XWorm v7.2 campaign highlights a persistent and uncomfortable truth in cybersecurity: vulnerabilities do not expire just because they are old. CVE-2018-0802 continues to be weaponized because organizations still fail to fully inventory and update all Office installations, especially on legacy systems and remote endpoints.

Excel Add-Ins Are the New Macro Blind Spot

Security awareness training often focuses heavily on macros, but Excel add-ins receive far less attention. Attackers understand this gap and are increasingly abusing .XLAM files to slip past user suspicion and automated defenses. Expect this technique to become more common as macro protections improve.

Living-Off-the-Land Techniques Are Winning the Stealth War

By relying on Msbuild.exe, attackers reduce their operational footprint and inherit Microsoft’s trust. This is not about sophisticated zero-days; it is about clever abuse of what already exists on almost every Windows machine. Defenders who still rely primarily on signature-based detection are fighting yesterday’s war.

Fileless Malware Is No Longer an Edge Case

XWorm’s fileless execution model is now mainstream among commodity malware families. Memory-resident threats allow attackers to move faster, stay hidden longer, and cleanly exit when needed. This demands wider adoption of endpoint detection and response solutions that can inspect runtime behavior and memory artifacts.

The Convergence of Crimeware Capabilities

The same implant offering remote access, ransomware, and DDoS functionality reflects a broader trend: modular crimeware ecosystems. Threat actors no longer specialize narrowly; they deploy adaptable toolkits that can shift objectives mid-operation depending on opportunity.

Why This Matters Beyond This Campaign

Even if this specific phishing wave is disrupted, the techniques it uses will persist. Old vulnerabilities, trusted binaries, and user-facing document formats remain fertile ground for attackers. Organizations that fail to evolve their detection strategies will continue to be exposed to low-cost, high-impact intrusions.

🔍 Fact Checker Results

✅ The campaign uses Excel .XLAM attachments to deliver the initial payload.
✅ CVE-2018-0802 enables remote code execution in unpatched Microsoft Office environments.
❌ There is no evidence that this campaign relies on newly discovered zero-day vulnerabilities.

📊 Prediction

The abuse of Excel add-ins and trusted Windows binaries will accelerate throughout 2026, especially in phishing campaigns targeting enterprises with mixed patch levels. As defenders harden macro defenses, attackers will continue shifting toward overlooked file formats and fileless execution paths, making behavioral and memory-based detection no longer optional but essential.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon