News
Scammers are still able to use Microsoft Excel to push malware

- June 29, 2022
- Updated: July 2, 2025 at 3:36 AM

Excel macros can help you save time by doing repetitive tasks for you on your spreadsheets. These actions include types of data manipulation you do frequently when compiling reports. Unfortunately, however, malicious actors have also been using Excel macros as vectors for passing on malware. To fight this, earlier this year, Microsoft disabled Excel macros 4.0 by default but it looks like scammers are still able to target Excel users via macros, let’s dig into this a little more.
Researchers at cybersecurity specialists Netskope have released a report that outlines how Excel files are still being used for malicious reasons. They stated that they have discovered a lot of dangerous Excel documents that can target users of older and, therefore, unprotected versions of Microsoft Excel.
The infected macros they discovered are carrying a well-known trojan called Emotet, which is capable of stealing the victim’s information and then dropping further instances of malware onto the device.
Gustavo Palazolo, the lead researcher at Netskope, who published the report, had this to say on the extent of the vulnerability:
“we found 776 malicious spreadsheets submitted between June 9, 2022 and June 21, 2022, which abuse Excel 4.0 (XLM) macros to download and execute Emotet’s payload. Most of the files share the same URLs and some metadata. We extracted 18 URLs out of the 776 samples, four of which were online and delivering Emotet.”
Basically, this all means that scammers are sending out Excel spreadsheets that are infected with a trojan malware called Emotet that infects devices and networks it finds its way onto. This means that once again, we are talking about a phishing scam and the best way to defend against it, as well as ensuring you’re running the latest version of Excel, is to stop it from infecting your device in the first place.
Phishing scams try to catch you out with fake links. In this particular case, potential victims receive emails containing attachments like payment forms or other types of spreadsheet. This means that to stay alert to this scam you need to know how to spot phishing scams. To learn how to do so, check out our guide to spotting fake email scams.
Patrick Devaney is a news reporter for Softonic, keeping readers up to date on everything affecting their favorite apps and programs. His beat includes social media apps and sites like Facebook, Instagram, Reddit, Twitter, YouTube, and Snapchat. Patrick also covers antivirus and security issues, web browsers, the full Google suite of apps and programs, and operating systems like Windows, iOS, and Android.
Latest from Patrick Devaney
You may also like
- News
'Catwoman' not only killed DC in cinema for years. It also destroyed a legendary video game studio
Read more
- News
Disney stopped this adaptation of one of its best animated films. Now it has restarted it
Read more
- News
Game Pass announces the first batch of games for October, including two classic RPGs and the most anticipated action game of the year
Read more
- News
Dwayne Johnson and Emily Blunt have a special chemistry on screen, and this classic available on Disney+ proves it
Read more
- News
EA alienates its community again with an overpriced cosmetic pack, this time in skate
Read more
- News
Sigourney Weaver was about to not appear in one of the Alien movies, but her director prevented it
Read more