216.73.217.22

Excel(ent) Obfuscation: Regex Gone Rogue

· Published 15/05/2025 14:08 · Modified 21/05/2025 20:30

Export JSON

Essential information

Published
15/05/2025 14:08
Modified
21/05/2025 20:30
Tags
2025-05-15 evasion excel macro obfuscation powershell regex regexextract vba
Related entities
3 observables, 9 techniques (mitre)

Description

A new -based attack technique leverages recently introduced functions for advanced code . The proof-of-concept demonstrates how malicious actors can use to hide commands within large text blocks, significantly reducing antivirus detection rates. This method outperforms traditional techniques, dropping VirusTotal detections from 22 to just 2. The approach also evades heuristic analysis tools like OLEVBA. While currently limited by Microsoft's default security and the functions' limited availability, this technique could potentially be combined with more sophisticated attack methods as it becomes more widely accessible.

External references