In recent weeks, SophosLabs has published papers outlining threats from AKBuilder and Betabot. Now, it appears the bad guys are combining the two in new attack campaigns. The documents initially drop a file that contains two payloads: one, the popular LokiBot credential stealer; the other, something that appears to be a version of BetabOT. The malware is delivered in email messages like this: “Gbor Szappanos said the lab has received and analyzed a handful of AKBuilder-generated documents in the past week.”]