Microsoft security has investigated an attack by malicious actors targeting various cryptocurrency investment firms. The threat actor, tracked as DEV-013, targeted cryptocurrency investment firms via a Telegram chat group, posing as a representative of another crypto investment firm to solicit feedback on the fee structure used by the cryptocurrency trading platform. After gaining the trust of the target, DEV-0139 sends a weaponized Excel file named OKX Binance & Huobi VIP fee comparison.xls, the data in the document is likely to be accurate, but it also contains a malicious code in an invisible Execute another Excel sheet in .mode, which allows the threat actor to remotely access the victim's infected system.