Threat actors have updated their malware to include a macro-based delivery framework.
Source: Threadpost