Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 13:45:42 UTC Home > List all groups > List all tools > List all groups using tool Aggah Tool: Aggah Names Aggah Category Malware Type Loader Description (DeepInstinct) Aggah is distributed by Microsoft Office documents with malicious VBA macros in them. In this campaign we have seen several PowerPoint presentations, some with Covid-19 related names, and others are invoices. The presentations are usually empty of content, besides a short and simple VBA macro that uses a StrReverse function to evade basic detection by AV products. Once opened it downloads the next stage of the malware via the “Shell” command. Information Last change to this tool card: 29 May 2020 Download this tool card in JSON format All groups using tool Aggah Changed Name Country Observed APT groups Aggah [Unknown] 2018-Jun 2022 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=25e618dd-f936-4ce3-9c9c-5f6e6cb8ec9c https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=25e618dd-f936-4ce3-9c9c-5f6e6cb8ec9c Page 1 of 1