Palo Alto Networks' Unit 42 reported a high-volume spam campaign delivering malicious Microsoft Word documents that used macros to launch hidden PowerShell and inject malware directly into memory, a fileless-style technique the researchers dubbed PowerSniff. The emails were socially engineered with victim-specific details and were sent about 1,500 times, primarily targeting organizations in the United States, with notable impact on the professional, hospitality, and manufacturing sectors.
The macro abused WMI to spawn a concealed PowerShell process that fetched architecture-specific payloads from rabbitons[.]pw, decoded shellcode, and loaded an embedded payload. The malware then performed anti-analysis checks, host reconnaissance, and victim profiling to avoid healthcare and education targets while prioritizing systems linked to point-of-sale activity and financial transactions; if command-and-control communication succeeded, it decrypted a DLL, saved it under AppData\LocalLow as a randomly named .db file, and executed it through rundll32.exe using the Register export. Researchers said the infrastructure was inactive during analysis and noted behavioral similarities to the Ursnif malware family.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Unit 42 disclosed technical details showing the macro used WMI to spawn hidden PowerShell, downloaded architecture-specific payloads from rabbitons[.]pw, performed anti-analysis and victim profiling, and attempted to retrieve an encrypted DLL from embedded C2 servers. The researchers also noted behavioral similarities to the Ursnif malware family and said no C2 servers were responsive during analysis.
Palo Alto Networks Unit 42 reported a high-threat spam campaign using malicious Microsoft Word documents with macros that launched PowerShell and injected malware directly into memory. The researchers named the malware PowerSniff and said they had observed roughly 1,500 related emails, primarily targeting U.S. organizations.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.