Microsoft discloses a new attack by Chimborazo, a group that is distributing a malicious Excel document on a site requiring CAPTCHA to evade automated detection
Dan Goodin / Ars Technica :
Context & Ripple Effects
Microsoft's security advisories keep circling the same delivery channel: Office files. A Word exploit pushed to millions for Dridex bank fraud set the pattern in 2017, and a zero-day abusing Office through IE's engine followed in 2021 — documents remain the reliable lure because users open them by habit.
The Chimborazo disclosure adds a new evasion layer to that playbook. Where threat actors misusing OAuth apps automated phishing at scale, this group goes the other way: a CAPTCHA wall on the hosting site filters out the automated crawlers that security vendors use to find and detonate malicious files, reserving the payload for real human victims.
First-order effects
- Organizations whose defenses lean on automated URL and attachment scanning will miss the campaign entirely — the CAPTCHA gate means the malicious Excel document never renders for their crawlers, so detection falls to the end user opening the file.
Second-order effects
- Email-security and threat-intelligence vendors have to build CAPTCHA-bypassing fetch capabilities or lean harder on user-reported samples, raising their cost per campaign; rival threat groups watching Microsoft's disclosure get a free blueprint for gating their own lure sites.
Third-order effects
- If human-verification walls become standard on malware hosting, the industry's detection economics shift: automated analysis at scale loses coverage, pushing defenders toward endpoint behavior detection and user reporting as the primary tripwires — a structural arms race between crawler-based scanning and attacker-side filtering.
The trend: Office-document malware delivery is evolving from raw exploits toward evasion of automated analysis itself, with Microsoft's advisories documenting each rung — from macro lures to zero-days to now CAPTCHA-gated hosting.