From gbhackers.com
A new phishing email campaign contained a malicious word document with macros downloads and executes Ursnif malware and GandCrab ransomware.
Security researchers from Carbon Black observed the campaign in wild and roughly 180 variants detected.
The first stage of attack starts in delivering of weaponized MS word document to deliver the initial stages, according to metadata it appears the documents prepared on December 17, 2018, and continues up to January 21, 2019. Documents found embedded with VBS macros that contain 18 lines of VBScript