[ << ALL_FEED ]

.exe .docm .xlsm

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

  • Ding, ding — who's there?

    Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…

.exe .docm .xlsm

Malicious files with these extensions are most often found in corporate network traffic. Let’s take a basic look at why.

🖥 .exe — the classic executable file extension in Windows: double-click — and you launch Fortnite (no judgment), your browser, your favorite messenger, an installer, or any other program. Or you might launch a Trojan or some other piece of malware.

Most of the time you don’t even see that the file has this extension: by default, Windows has the “Hide extensions for known file types” feature enabled, so you only see the first part of the name. And attackers take advantage of this.

For example, they disguise a file as something harmless: instead of zarplaty_sep_2026.pdf.exe, you’ll just see zarplaty_sep_2026.pdf. It doesn’t raise suspicion, but it does spark curiosity. Click-click — and boom.

Anyway, for self-protection we recommend disabling this feature. It’s easy to do, and you’ll always know exactly what you’re clicking on.

📄 .docm and .xlsm — and these are the Microsoft Office document extensions familiar to every office worker. They’re often sent around via email, chats, and USB drives, so they usually don’t raise suspicion.

But something’s off with the last letters of these extensions — you might say, and you’d be right. Instead of an x at the end, there’s an m, which means these documents support macros — small programs in a special language called VBA that can perform actions inside the document. You may also come across the extensions .dotm and .xltm — these are document templates with macro support.

And just like with .exe, these extensions are hidden by default in Windows file names, so you just see the document icon and its name.

Macros are a useful thing that helps automate routine actions in documents (enthusiasts have even managed to run DOOM right inside Word with them).

But attackers use them too: you open what seems like an ordinary file, allow macros — and the commands embedded in them execute on your computer. For example, they can run a system command that downloads and launches another piece of malware.

So here’s why we decided to explain all this

1️⃣ Carefully watch what exactly you’re launching and what permissions you’re granting.

2️⃣ Our experts, using the PT Sandbox sandbox, analyzed malicious activity detected by PT NAD in the network traffic of organizations from October 2025 to July 2026. And 29% of dangerous files turned out to have the .exe, extension, while 26% had Microsoft Office extensions.

3️⃣ As you can imagine, these files are just the tip of the malware iceberg. Below in the networks, potentially dangerous tools that look legitimate were also discovered, along with various archive variations and more interesting finds.

You can read about them in the full version of the study on our website.

#malware
@ptescalator

More from global_author

More from global_author

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

  • Ding, ding — who's there?

    Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…