A new variant of the FileFix malware has been discovered delivering the Stealc information-stealing malware through malicious Excel macros. This attack vector leverages social engineering to trick users into enabling macros, which then execute the Stealc payload. Stealc is known for harvesting sensitive data including credentials, browser information, and cryptocurrency wallets. The campaign highlights the persistent threat of macro-based malware and the importance of user awareness and robust endpoint protection. Organizations are urged to implement strict macro policies and educate employees about the risks of enabling macros from untrusted sources. The FileFix variant's use of Excel macros underscores the evolving tactics of cybercriminals to bypass traditional security measures and target valuable data assets. Continuous monitoring and threat intelligence sharing are critical to defend against such sophisticated malware campaigns.
This Cyber News was published on thehackernews.com. Publication date: Tue, 16 Sep 2025 22:14:03 +0000