Skip to content
July 5, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Hackers use IQY file to bypass AV and download malware through Microsoft Excel
  • Malware

Hackers use IQY file to bypass AV and download malware through Microsoft Excel

Do Son June 12, 2018 3 minutes read
IQY file
Add as a preferred
source on Google

According to an article posted by the technology blog Barkly last week, security researcher Derek Knight (@dvk01uk) has discovered a series of new spam email campaigns using a more novel approach to infect victims. Instead of using Word documents or other types of attachments that are often abused, these activities use Web query files (.iqy)—essentially simple text files that are opened by default in Microsoft Excel for download data from the Internet.

Excel expert Jon Wittwer’s comment on the .iqy file was “basically like having a web browser built into Excel.” The danger is that it can be misused to package powerful utilities into an extremely simple and legal file format, which is not enough to cause anti-virus software to respond. As Derek Knight points out, “These blow past all antiviruses because they have no malicious content.“

In this series of spam e-mail activities discovered by Derek Knight, the .iqy file downloads a PowerShell script that is launched via Microsoft Excel and performs a series of malicious downloads.

The first batch of spam emails using .iqy files was issued on May 25, 2018, from Necurs, the world’s largest spam botnet. Subsequently, a smaller peak was detected on June 5, 2018. Only two days later, on June 7, 2018, Derek Knight found the third wave of activity.

E-mails that appear in all these activities have little and no text. This is a typical type of spam email. For example, in the first wave event, the subject of the mail is “Unpaid invoice [ID: xxxxxxxxx]”, the text is completely free of any content, and it looks like it is from insiders of the target organization.

As mentioned earlier, almost all virus-killing software seems to be meaningless in the face of .iqy files. According to VirusTotal, the .iqy file that appeared in the first wave of events was completely undetected on the day. Until Derek Knight announced his findings through Twitter, antivirus software began to be detected in the next day.

When it is opened, the .iqy file is started with Microsoft Excel and attempts to extract data from the internally contained URL. As Jon Wittwer pointed out, the basic form of .iqy files is very simple. For example, opening a .iqy file that appears in a second wave event in Notepad looks like this (just a few lines of text):

 

A .xls file will be downloaded, which is actually a disguised .exe file. The final payload is Flawed Ammyy, a remote-access Trojan (RAT) discovered by cybersecurity firm Proofpoint.

FlawedAmmyy is built from the source code leaked by the popular remote desktop software Ammyy Admin. It has many features that provide Ammyy Admin. In simple terms, it basically allows the attacker to gain full access to the infected computer, allowing them to steal files and credentials, hijack the computer to send more spam emails, and so on.

We recommend that administrators should adjust firewall and email filtering rules in time to block .iqy files. In addition, unless you need to use .iqy files frequently, it is wise to further set up Windows to always open .iqy files in Notepad.

Source, Image: Barkley

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • APT10’s Latest Weapon: Unveiling the LODEINFO Malware Menace
  • AI-Generated RAT “PHANTOMPULSE” Targets Crypto Sector via Social Engineering
  • 0bj3ctivityStealer: Stealthy Info-Stealer Uses Steganography & PowerShell to Evade Detection
  • SophosLabs found adware on seven apps with over 500,000 downloads
  • Microsoft Acts Against Malware: MSIX ms-appinstaller Handler Disabled

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: IQY file

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-48282CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted...
    Admin intel📅 Updated: Jul 3, 2026
  • CVE-2024-14037CVSS 9.8
    Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution...
    Admin intel📅 Updated: Jul 3, 2026
  • CVE-2026-8451CVSS 8.8
    Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured...
    Admin intel📅 Updated: Jul 2, 2026
  • CVE-2026-8037CVSS 9.6
    OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to...
    Admin intel📅 Updated: Jul 1, 2026
  • CVE-2026-45659CVSS 8.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 1, 2026
  • CVE-2026-48558CVSS 10.0
    SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication...
    Admin intelCISA KEV📅 Added to KEV: Jun 29, 2026📅 Updated: Jun 29, 2026
  • CVE-2026-46817CVSS 9.8
    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected...
    Admin intel📅 Updated: Jun 29, 2026
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
    Admin intel📅 Updated: Jun 25, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-58426CVSS 9.6
    Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read...
  • CVE-2026-58289CVSS 9.0
    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based)...
  • CVE-2026-22874CVSS 9.6
    Gitea versions up to and including 1.26.2 have incomplete SSRF protection in...
  • CVE-2026-20896CVSS 9.8
    Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by...
  • CVE-2026-4321CVSS 9.8
    Improper neutralization of special elements used in an SQL command ('SQL injection')...
  • CVE-2026-14544CVSS 9.8
    A flaw was found in HPLIP (HP Linux Imaging and Printing Software)....
  • CVE-2026-9725CVSS 9.1
    The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress...
  • CVE-2026-13768CVSS 10.0
    Gardyn devices expose a privileged iothubowner key. Access to this key will...
  • CVE-2026-57100CVSS 9.9
    Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an...
  • CVE-2026-45499CVSS 9.9
    Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.