Excel(ent) Obfuscation: Regex Gone Rogue
May 21, 2025, 8:30 p.m.
Description
A new Excel-based attack technique leverages recently introduced regex functions for advanced code obfuscation. The proof-of-concept demonstrates how malicious actors can use REGEXEXTRACT to hide PowerShell commands within large text blocks, significantly reducing antivirus detection rates. This method outperforms traditional obfuscation techniques, dropping VirusTotal detections from 22 to just 2. The approach also evades heuristic analysis tools like OLEVBA. While currently limited by Microsoft's default macro security and the functions' limited availability, this technique could potentially be combined with more sophisticated attack methods as it becomes more widely accessible.
Tags
Date
- Created: May 15, 2025, 2:08 p.m.
- Published: May 15, 2025, 2:08 p.m.
- Modified: May 21, 2025, 8:30 p.m.
Indicators
- 5af1bd3d95e6307d95e9973aa4a084ae210f9038cbea2235d14b02d97abd4f2b
- dedbe856891dd633ce3dd66ecc120ef4f1ae0a61a37dbb4cc6a59f7eae7019d9
- 2c99e702609d549440952ef72f2386a74e0da1462df65ab4206f44c94e8dbc72