Site icon WinCert

Microsoft’s One Note attachments can spread malware

<p>With Microsoft Authentication and Microsoft blocking VBA macros in Office by default&comma; hackers are constantly in pursuit of new solutions to breach and access sensitive user data&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-3203" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;07&sol;hacker&period;jpg" alt&equals;"" width&equals;"640" height&equals;"426" &sol;><&sol;p>&NewLine;<p>Apparently now&comma; hackers have found a new way to spread malware to inexperienced users using the Microsoft OneNote app&period; Considering Microsoft has placed the VBA block on macros in Office&comma; hackers are now trying to mask its malware as legitimate documents&period; In this way&comma; inexperienced users could lower their security and enable macros trying to enhance accessibility and thus exposing them to threats&period;<&sol;p>&NewLine;<p>According to the <a href&equals;"https&colon;&sol;&sol;www&period;bleepingcomputer&period;com&sol;news&sol;security&sol;hackers-now-use-microsoft-onenote-attachments-to-spread-malware&sol;" target&equals;"&lowbar;blank" rel&equals;"noopener">Bleeping Computer report<&sol;a>&comma; the hackers are now sending phishing emails containing DHL invoices&comma; shipping documents&comma; remittance forms&comma; etc&period;<&sol;p>&NewLine;<p>Once a user double-clicks on the attachment&comma; Windows will warn the user that opening the attachment could harm the PC and its data&period; If a user chooses to ignore this message and opens the attached file&comma; malicious VBS found in the OneNote notebook will be downloaded to the PC&period;<&sol;p>&NewLine;<p>Once the OneNote file has been opened&comma; the user will get another prompt to Double Click to View File&period; Upon execution of this request&comma; things start to get ugly because at that point malicious batch file is being executed in the background which will compromise PC&&num;8217&semi;s security&period; Once attackers gain access to your machine they will be able to access saved passwords and other sensitive data&period;<&sol;p>&NewLine;<p>To stay safe&comma; please refrain from opening emails and attachments from unknown senders&period;<&sol;p>&NewLine;

Exit mobile version