VORANT. Threat Intelligence Sign in Get the full feed

Bitcoin lure macro doc targets macOS Office

medium threat financial-services

A malicious Word macro doc lures Bitcoin/crypto professionals, escapes Word's macOS sandbox, and drops a Meterpreter stager via Python.

A Word document named BitcoinMagazine-Quidax_InterviewQuestions_2018.docm was discovered targeting macOS Office users under the guise of a Bitcoin interview questionnaire. Analysis of the embedded VBA macro revealed it uses libc.dylib's popen function to call system(), reproducing a previously published sandbox-escape technique (from a guest blog by Adam Chester) to write a malicious LaunchAgent plist to disk, bypassing Word's macOS sandbox restrictions that normally prevent persistence.

The LaunchAgent executes a base64-encoded first-stage Python payload that repeatedly attempts to connect to a remote server at 109.202.107.20 on port 9622, retrieving a second-stage payload over the socket. Analysts decoded and executed the retrieved payload, identifying it as Metasploit's Meterpreter, giving the attacker a feature-rich in-memory implant capable of arbitrary command execution, file exfiltration, and further post-exploitation activity. The IP address hosting the payload has been previously flagged as malicious infrastructure.

At time of analysis only 5 antivirus engines detected the sample as malicious, indicating low detection coverage for this macOS-targeted campaign. The lure theme (cryptocurrency/Bitcoin interview) suggests targeting of individuals or organizations in the crypto/financial space, though no specific victim organization or attribution is confirmed in the source material.

Mentioned in this report

Malware Meterpreter

Source reporting: https://objective-see.org/blog/blog_0x3A.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free