
In June 1997, I joined Sophos and while not initially employed as virus analyst I became heavily involved in the virus lab (what was later to be branded SophosLabs). One of the people working there I had known at University (Martin S) and when he got bored with macro analysis I started on my malware journey writing detection for and replicating macro viruses.
My first signature was a modification for one of the WM/Cap detections but the more prevalent family of macros was on Excel and was called Laroux. The earliest signature for Laroux, I wrote was 29th Jan 1998, and was for what Sophos would call1 XM/Laroux-J. Over the next decade, I would go on to write detections for 100s of macro viruses. After Sophos bought ActiveState in 2003, I moved into spam detection this move coincided with a gradual strengthening of MS Office security and a decline in macro viruses. Since June 2013, I have been working at Proofpoint with a primary focus on spam but still writing detections for macro trojans.
Why am I talking about Laroux? Well earlier this month a customer sent a copy of a macro virus not detected by their AV solution. This meant that:
.XM97Laroux.220303;Engine:81-255,Target:2
24 years after I first wrote a detection for Laroux I have written another. In that time my life has changed but the threat-landscape is still heavily dominated by Office malware.
1 Nomenclature debates still occur within malware detectors.
Thanks to Fraser for digging out the date of my oldest Laroux.
Filed under: Uncategorized | Tagged: excel, laroux | Leave a comment »




Networks are a dark art and to truly understand them you must practise by analysing packets. Like Harry and friends in Dumbledore’s Army found that book learning, classroom learning isn’t sufficient alone. This book, doesn’t get bogged down in the minutiae but uses walked through examples to teach directly. In fact, nearly two-thirds of the book is the examples and while SANS “
