
- Group-IB links a macro-based phishing campaign to Iranian threat actor MuddyWater
- Attackers used fake emails and Word docs to deploy Phoenix v4 and other malware
- Despite macro blocking since 2022, outdated techniques are still being used in the wild
It’s October 2025, yet some cybercriminals are still trying to deliver malware via Microsoft Word macros, experts have warned.