← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs
An XLL is a native Windows DLL that Excel loads as an add-in, allowing it to execute arbitrary code through exported functions like xlAutoOpen. Since at least mid-2017, threat actors began abusing Microsoft Excel add-ins via the .XLL format, the earliest documented misuse is by the threat group APT10 (aka Stone Panda / Potassium) injecting backdoor payloads via XLLs.
Indicators of Compromise (14 / 20 total)