SophosLabs have come across a Microsoft Excel based Sudoku generator spreadsheet that tricks victim into running the malware.
"if you want to generate a puzzle to solve, you have to enable macros. It sounds perfectly reasonable, doesn't it? Generating Sudoku puzzles requires a program; to run the program requires macros." Researcher said in the nakedsecurity.
Once you enabled the macros, in the background a rather less amusing macro is installing and running some malware.
The malware collects system information using standard commands: ipconfig to get network information, tasklist for a list of all the programs and services you are running, and systeminfo to find out about your hardware, operating system and patches.
Once the data is collected, the malware starts to send data to an aol.com address.