Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Dridex Distributed with "Merry Christmas!" Excel File

December 29, 2021

The downloaded Excel file has information about 'Christmas Bonus', and has hidden sheets that use the Cell Formula method mainly used for Excel macro malware. The attached file for the 'Termination of employment' email has the name 'TerminationList.xls' but has details about 'Christmas bonus.' As such, it appears that the emails are distributed randomly without any coherency. Through the Name Manager tool of the Excel file, it can be assumed that Auto_Open macro will have its code operating based on the values from the hidden 'Macro1' and 'Sheet1' sheets. Column V of the 'Macro1' sheet has a macro code written with Cell Formula. 'Sheet1' has the data saved in decimal, which is changed to text form and then combined. The following shows a formula for using rows 163 to 4975 of column BH in 'Sheet1' to combine malicious data.