VBREVSHELL

Malware type
webshell
Profile updated
2026-07-07 13:08:56

Context

According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.

Reports & references

  • socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
  • Mandiant — 17826 (report)
  • malpedia.caad.fkie.fraunhofer.de — Vbs.Vbrevshell (report)
  • linkedin.com — Urn:Li:Activity:7137086303329783808 (report)

External references