/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft discloses a new attack by Chimborazo, a group that is distributing a malicious Excel document on a site requiring CAPTCHA to evade automated detection

Dan Goodin / Ars Technica :

Ars Technica Dan Goodin

Context & Ripple Effects

Microsoft's security advisories keep circling the same delivery channel: Office files. A Word exploit pushed to millions for Dridex bank fraud set the pattern in 2017, and a zero-day abusing Office through IE's engine followed in 2021 — documents remain the reliable lure because users open them by habit.

The Chimborazo disclosure adds a new evasion layer to that playbook. Where threat actors misusing OAuth apps automated phishing at scale, this group goes the other way: a CAPTCHA wall on the hosting site filters out the automated crawlers that security vendors use to find and detonate malicious files, reserving the payload for real human victims.

First-order effects

  • Organizations whose defenses lean on automated URL and attachment scanning will miss the campaign entirely — the CAPTCHA gate means the malicious Excel document never renders for their crawlers, so detection falls to the end user opening the file.

Second-order effects

  • Email-security and threat-intelligence vendors have to build CAPTCHA-bypassing fetch capabilities or lean harder on user-reported samples, raising their cost per campaign; rival threat groups watching Microsoft's disclosure get a free blueprint for gating their own lure sites.

Third-order effects

  • If human-verification walls become standard on malware hosting, the industry's detection economics shift: automated analysis at scale loses coverage, pushing defenders toward endpoint behavior detection and user reporting as the primary tripwires — a structural arms race between crawler-based scanning and attacker-side filtering.

The trend: Office-document malware delivery is evolving from raw exploits toward evasion of automated analysis itself, with Microsoft's advisories documenting each rung — from macro lures to zero-days to now CAPTCHA-gated hosting.

Discussion

  • @reybango Rey Bango on x
    Many threat hunters will use automated tools to download malware and analyze them in a VM. Bad actors are trying to make it more difficult by using CAPTCHAS: “To evade detection, hackers are requiring targets to complete CAPTCHAs” https://arstechnica.com/... via @dangoodin001
  • @dez_blanchfield Dez Blanchfield on x
    To evade detection, hackers are requiring targets to complete CAPTCHAs ( this is pure genius ) https://arstechnica.com/...