{"id":42047,"date":"2015-03-18T11:51:29","date_gmt":"2015-03-18T18:51:29","guid":{"rendered":"https:\/\/blogs.mcafee.com\/?p=42047"},"modified":"2025-08-15T09:15:02","modified_gmt":"2025-08-15T16:15:02","slug":"bartallex-renews-strain-of-macro-malware","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/","title":{"rendered":"Bartallex Renews Strain of Macro Malware"},"content":{"rendered":"<p>In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware families that serves these embedded macros is Bartallex, whose appearances have increased significantly during this period. The following chart shows the recent trend for the family:<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/111.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42048\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/111.jpg\" alt=\"11\" width=\"597\" height=\"356\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/111.jpg 597w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/111-300x179.jpg 300w\" sizes=\"auto, (max-width: 597px) 100vw, 597px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Background<\/strong><\/h2>\n<p>This threat is a malicious macro\u00a0that comes into users&#8217; systems through a spam email and a Microsoft Word file, which leads to downloading and running the malware on the victim\u2019s machine. Whenever a user tries to open\u00a0the malicious doc file, Word should show a security notification asking whether the user wants to enable macros. If enabled, this threat will execute.<\/p>\n<p>One difference in this variant of W97MDownloader is that it clears the contents in the Word document after the macro is enabled. It also generally downloads its payload in the %temp% folder.<\/p>\n<p>The spam email may look like this:<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/23.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42050\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/23.jpg\" alt=\"2\" width=\"729\" height=\"375\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/23.jpg 729w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/23-300x154.jpg 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Infection Chain<\/strong><\/h2>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/16.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42104\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/16.jpg\" alt=\"1\" width=\"816\" height=\"272\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/16.jpg 816w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/16-300x100.jpg 300w\" sizes=\"auto, (max-width: 816px) 100vw, 816px\" \/><\/a><\/p>\n<p>This threat shows that attackers have not forgotten the classic exploitation technique of tricking users into enabling Office macros to execute malicious code.<\/p>\n<p>The infection chain starts with the spammed email. The email is carefully designed to lure users and seems legitimate. After executing, Bartallex drops a .bat file and a .vbs file onto the victim&#8217;s system. They download further malware.<\/p>\n<p>The following figure shows a .doc file with embedded macro posing as a fax:<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/32.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42055\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/32.jpg\" alt=\"3\" width=\"1219\" height=\"660\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/32.jpg 1219w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/32-300x162.jpg 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/32-1024x554.jpg 1024w\" sizes=\"auto, (max-width: 1219px) 100vw, 1219px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>If email recipients open the document, they first see junk data with a request to enable the macro&#8211;in spite of the security warning to not trust its content. The doc file has a random\u00a0name, for example:<\/p>\n<ul>\n<li>invoice_985861.doc<\/li>\n<li>fax=5Fmsg759-746-3956.doc<\/li>\n<li>legal_complaint.doc<\/li>\n<li>logmein_coupon.doc<\/li>\n<li>receipt_3458764.doc<\/li>\n<\/ul>\n<p>Upon execution, this malware drops the following files:<\/p>\n<ul>\n<li>%Temp%\\adobeacd-update.bat<\/li>\n<li>%Temp%\\adobeacd-updatexp.vbs<\/li>\n<\/ul>\n<p>The downloaded files are:<\/p>\n<ul>\n<li>%Temp%\\444.exe (for Windows XP and earlier)<\/li>\n<li>%User Temp%\\444.exe (for Windows Vista and later)<\/li>\n<\/ul>\n<h2><strong>Extracting the Macro<\/strong><\/h2>\n<p style=\"text-align: center;\"><strong>\u00a0<a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/41.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42058\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/41.jpg\" alt=\"4\" width=\"640\" height=\"194\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/41.jpg 640w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/41-300x91.jpg 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/strong><\/p>\n<p>This document contains three embedded macros. The details of the extracted macros follow:<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/51.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42059\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/51.jpg\" alt=\"5\" width=\"908\" height=\"298\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/51.jpg 908w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/51-300x98.jpg 300w\" sizes=\"auto, (max-width: 908px) 100vw, 908px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Let&#8217;s take a look some of this malware&#8217;s evasion efforts. The first two lines use some classic obfuscation.<\/p>\n<ul>\n<li>BART212 = &#8220;&#8221; &amp; &#8220;d-up&#8221; + &#8220;date&#8221;<\/li>\n<li>BART2 = Chr (97) + Chr (100) &amp; &#8220;&#8221; &amp; &#8220;o&#8221; &amp; &#8220;&#8221; &amp; &#8220;b&#8221; &amp; &#8220;e&#8221; + &#8220;ac&#8221; &amp; BART212<\/li>\n<\/ul>\n<p>Splitting a variable is typical for evading scanners searching for keywords and other suspicious activities such as downloading a file. The Chr function returns a string containing the character associated with the specified character code. For example, Chr (97) is the letter <em>a<\/em> and Chr (100) is the letter <em>d<\/em>.<\/p>\n<p>After removing the breaks and making the substitutions, we see a meaningful string:<\/p>\n<p>BART2 = &#8220;adobeacd-update&#8221;<\/p>\n<h2><strong>Payload<\/strong><\/h2>\n<p>Opening the document file with macros enabled runs the dropped batch file, which in turn runs the .vbs file, which immediately downloads other malware&#8211;such as malware families Upatre, Vawtrak, and Chanitor&#8211; from the remote server.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/61.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-42060 aligncenter\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/61.jpg\" alt=\"6\" width=\"547\" height=\"385\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/61.jpg 547w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/61-300x211.jpg 300w\" sizes=\"auto, (max-width: 547px) 100vw, 547px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/71.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42061\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/71.jpg\" alt=\"7\" width=\"595\" height=\"499\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/71.jpg 595w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/71-300x252.jpg 300w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><\/a><\/p>\n<p>The malware connects to the control server \u201chttps:\/xx.xxx.254.213\/us\/file.jpg\u201d and downloads the payload, which appears to be a .jpg file but is really a malicious .exe file.<\/p>\n<p>Here&#8217;s a look at the traffic:<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/81.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-42062\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/81.jpg\" alt=\"8\" width=\"1287\" height=\"618\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/81.jpg 1287w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/81-300x144.jpg 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/81-1024x492.jpg 1024w\" sizes=\"auto, (max-width: 1287px) 100vw, 1287px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>We have also seen this threat download a clean PNG image file and save it with a random file name, for example\u00a0%temp%\\savepic.su\\5123965.png.<\/p>\n<p>We are seeing lot of malware propagating through this infection vector. It&#8217;s always a good idea to pay attention to system security messages. Don&#8217;t ignore a suggestion to be careful.<\/p>\n<p>McAfee products detect this threat and its payloads as:<\/p>\n<ul>\n<li>W97M\/Downloader.aen<\/li>\n<li>Generic-FAWE! <em>[partial hash]<\/em><\/li>\n<li>Backdoor-FCMU! <em>[partial hash]<\/em><\/li>\n<\/ul>\n<p>I would like to thank my colleague Lenart Brave for his help with this analysis.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded&#8230;<\/p>\n","protected":false},"author":674,"featured_media":129703,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10661,13],"tags":[1814,3923,180],"coauthors":[3973],"class_list":["post-42047","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-security","category-privacy-identity-protection","tag-computer-security","tag-email-and-web-security","tag-malware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Bartallex Renews Strain of Macro Malware | McAfee Blog<\/title>\n<meta name=\"description\" content=\"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Bartallex Renews Strain of Macro Malware | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2015-03-18T18:51:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-15T16:15:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/111.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"597\" \/>\n\t<meta property=\"og:image:height\" content=\"356\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"McAfee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\"},\"author\":{\"name\":\"McAfee\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\"},\"headline\":\"Bartallex Renews Strain of Macro Malware\",\"datePublished\":\"2015-03-18T18:51:29+00:00\",\"dateModified\":\"2025-08-15T16:15:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\"},\"wordCount\":618,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg\",\"keywords\":[\"computer security\",\"email and web security\",\"malware\"],\"articleSection\":[\"Internet Security\",\"Privacy &amp; Identity Protection\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\",\"name\":\"Bartallex Renews Strain of Macro Malware | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg\",\"datePublished\":\"2015-03-18T18:51:29+00:00\",\"dateModified\":\"2025-08-15T16:15:02+00:00\",\"description\":\"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg\",\"width\":614,\"height\":300,\"caption\":\"virus scan looking for malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Internet Security\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/internet-security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Bartallex Renews Strain of Macro Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\",\"name\":\"McAfee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"caption\":\"McAfee\"},\"description\":\"We're here to make life online safe and enjoyable for everyone.\",\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/x.com\/McAfee\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Bartallex Renews Strain of Macro Malware | McAfee Blog","description":"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Bartallex Renews Strain of Macro Malware | McAfee Blog","og_description":"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware","og_url":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2015-03-18T18:51:29+00:00","article_modified_time":"2025-08-15T16:15:02+00:00","og_image":[{"width":597,"height":356,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/111.jpg","type":"image\/jpeg"}],"author":"McAfee","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/"},"author":{"name":"McAfee","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa"},"headline":"Bartallex Renews Strain of Macro Malware","datePublished":"2015-03-18T18:51:29+00:00","dateModified":"2025-08-15T16:15:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/"},"wordCount":618,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg","keywords":["computer security","email and web security","malware"],"articleSection":["Internet Security","Privacy &amp; Identity Protection"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/","url":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/","name":"Bartallex Renews Strain of Macro Malware | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg","datePublished":"2015-03-18T18:51:29+00:00","dateModified":"2025-08-15T16:15:02+00:00","description":"In recent weeks, McAfee Labs has seen a rise in the W97MDownloader malware, which comes with a macro downloader embedded in doc files. One of the malware","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#primaryimage","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/02\/614x300_VirusScan.jpg","width":614,"height":300,"caption":"virus scan looking for malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/internet-security\/bartallex-renews-strain-of-macro-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Internet Security","item":"https:\/\/www.mcafee.com\/blogs\/internet-security\/"},{"@type":"ListItem","position":3,"name":"Bartallex Renews Strain of Macro Malware"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa","name":"McAfee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","caption":"McAfee"},"description":"We're here to make life online safe and enjoyable for everyone.","sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/x.com\/McAfee"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/42047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/674"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=42047"}],"version-history":[{"count":3,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/42047\/revisions"}],"predecessor-version":[{"id":220011,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/42047\/revisions\/220011"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media\/129703"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=42047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=42047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=42047"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=42047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}