.. /.Xlam

Executable
Phishing
Doubleclick
Macros

Contributors:

Outflank @OutflankNL, Adithya - @ravooriadithya

Description:

A file with the XLAM file extension is an Excel Macro-Enabled Add-In file that's used to add new functions to Excel. Similar to other spreadsheet file formats, XLAM files contain cells that are divided into rows and columns that can contain text, formulas, charts, images, and more. Like Excel's XLSM and XLSX file formats, XLAM files are XML-based and saved with ZIP compression to reduce the overall size. Along with cybercrime groups, APTs like transparent tribe have been found leveraging .xlam file types to target their victims.

OS:

Windows
Mac

Recommendation:

Manage trusted locations (to an absolute minimum) and monitor remaining. Disable macros via GPO and whitelist the users that are permitted to run macros. For end-users, turn off macros from Excel's settings.

Resources:

https://outflank.nl/blog/2021/12/09/a-phishing-document-signed-by-microsoft
https://bazaar.abuse.ch/browse/tag/xlam/
https://blog.talosintelligence.com/2021/05/transparent-tribe-infra-and-targeting.html

File Samples:

https://www.virustotal.com/gui/file/53e060dbb6507e8e7bc6642db1afe14e91c82083e82cba85e54ed06a9a08485f