News
Scammers are still able to use Microsoft Excel to push malware

- June 29, 2022
- Updated: July 2, 2025 at 3:36 AM

Excel macros can help you save time by doing repetitive tasks for you on your spreadsheets. These actions include types of data manipulation you do frequently when compiling reports. Unfortunately, however, malicious actors have also been using Excel macros as vectors for passing on malware. To fight this, earlier this year, Microsoft disabled Excel macros 4.0 by default but it looks like scammers are still able to target Excel users via macros, let’s dig into this a little more.
Researchers at cybersecurity specialists Netskope have released a report that outlines how Excel files are still being used for malicious reasons. They stated that they have discovered a lot of dangerous Excel documents that can target users of older and, therefore, unprotected versions of Microsoft Excel.
The infected macros they discovered are carrying a well-known trojan called Emotet, which is capable of stealing the victim’s information and then dropping further instances of malware onto the device.
Gustavo Palazolo, the lead researcher at Netskope, who published the report, had this to say on the extent of the vulnerability:
“we found 776 malicious spreadsheets submitted between June 9, 2022 and June 21, 2022, which abuse Excel 4.0 (XLM) macros to download and execute Emotet’s payload. Most of the files share the same URLs and some metadata. We extracted 18 URLs out of the 776 samples, four of which were online and delivering Emotet.”
Basically, this all means that scammers are sending out Excel spreadsheets that are infected with a trojan malware called Emotet that infects devices and networks it finds its way onto. This means that once again, we are talking about a phishing scam and the best way to defend against it, as well as ensuring you’re running the latest version of Excel, is to stop it from infecting your device in the first place.
Phishing scams try to catch you out with fake links. In this particular case, potential victims receive emails containing attachments like payment forms or other types of spreadsheet. This means that to stay alert to this scam you need to know how to spot phishing scams. To learn how to do so, check out our guide to spotting fake email scams.
Patrick Devaney is a news reporter for Softonic, keeping readers up to date on everything affecting their favorite apps and programs. His beat includes social media apps and sites like Facebook, Instagram, Reddit, Twitter, YouTube, and Snapchat. Patrick also covers antivirus and security issues, web browsers, the full Google suite of apps and programs, and operating systems like Windows, iOS, and Android.
Latest from Patrick Devaney
You may also like
NewsThis free streaming service is standing up to the biggest players: how does it do it?
Read more
NewsArtificial intelligence is transforming advertising: for better?
Read more
NewsCan Blizzard make a comeback in 2026?
Read more
NewsThe best game of 2025 has been disqualified from the Indie Game Awards because of AI
Read more
NewsThis way you can make your internet browsing more sustainable: for a more eco-friendly 2026
Read more
NewsThey have just released one of the best movies of 2025 on SkyShotime: perfect for Christmas
Read more