New Orcinius Trojan Uses VBA Stomping to Mask Infection
New Orcinius Trojan Uses VBA Stomping to Mask Infection
02 July 2024
This multi-stage trojan utilizes Dropbox and Google Docs to update and deliver payloads. It uses the VBA stomping technique, removing the VBA source code in a Microsoft Office document, leaving only compiled p-code.