Netskope Threat Labs

Occamy

ATP Sandbox Adv. HeuristicsNetskope IPS

Occamy is a macro based downloader that delivers additional malware payloads onto infected systems. It arrives through malicious documents that rely on VBA macros, and users who enable content trigger the download of follow on payloads such as stealers and backdoors. Detections under this name indicate that a document executed its macro chain, and responders should hunt for the payloads it fetched.

First seen
January 2022
Last seen
October 2026
Alert Name
Android.Trojan.Occamy
ByteCode-JAVA.Trojan.Occamy
ByteCode-MSIL.Trojan.Occamy
Document-HTML.Trojan.Occamy
Document-RTF.Trojan.Occamy
Document-Word.Downloader.Occamy
Document-Word.Trojan.Occamy
Linux.Trojan.Occamy
Script-BAT.Trojan.Occamy
Script-JS.Trojan.Occamy