TABBYCAT

Description

(Mandiant) TABBYCAT is a Microsoft Word VBA macro that functions as a dropper. It relies on social engineering in order to be executed as a macro within a decoy Microsoft Word document. It decodes a payload embedded in a UserForm and launches it. TABBYCAT has been observed dropping the VBREVSHELL backdoor.

Names

Name
TABBYCAT

Category

Malware

Type

  • Dropper

Information

Other Information

Uuid

f2492a15-807d-4884-a9c5-26a237bad2bf

Last Card Change

2022-09-13