Friday, February 3, 2023
  • Login
No Result
View All Result
Atreju
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
No Result
View All Result
Atreju
No Result
View All Result
ADVERTISEMENT
Home Technology

Microsoft OneNote attachments are being used to spread malware

by Atreju
January 23, 2023
in Technology
0
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Hackers have discovered a new way to bypass the macro block in Microsoft Office files and still deliver malware (opens in new tab) to unsuspecting victims through the company’s suit of online collaboration apps. 

Security experts at BleepingComputer found freshly distributed phishing emails equipped with OneNote attachments. 

OneNote is a digital notetaking app, which people can use to create a sharable content library. It comes as part of the wider Microsoft Office suite, meaning if people have this installed, they can open OneNote files, too. While OneNote’s files, called NoteBooks, don’t support macros, they do support attachments, and that’s what the crooks are now leveraging.

Malicious VBS files

The phishing emails themselves are nothing out of the ordinary – they include fake DHL parcel notifications, fake invoices, fake shipping notifications, ACH remittance forms, and such. Instead of carrying a Word or Excel file attached, they carry a OneNote file which, if opened, seems to be blurred out, with a huge button in the middle saying “Double Click to View File”.

Double-clicking, however, runs the attachment which, in this case, is a malicious VBS file. 

This file then initiates communication with the command & control (C2) server and downloads the malware. 

BleepingComputer obtained a couple of these emails and determined that multiple remote access trojans and infostealers are being circulated, including the AsyncRAT and XWorm remote access trojans, as well as the Quasar Remote Access trojan.

The best way to protect against these attacks is the same as it always was – educate your employees not to download attachments and click on email links from people they don’t know, don’t trust, or whose identity cannot be confirmed. Also, they should be educated not to ignore warning messages prompted in programs such as Word, Excel, or OneNote. Other than that, having a strong antivirus solution, and a firewall, is welcome. 

Finally, activating multi-factor authentication (MFA) wherever possible greatly reduces the chances of more serious compromise. 

Via: BleepingComputer (opens in new tab)

Atreju

Atreju

Next Post
Logge massoniche, In Toscana sono 114, a Milano 38

Logge massoniche, In Toscana sono 114, a Milano 38

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

19 YoPlayDo Alternatives - Just Alternative To

19 YoPlayDo Alternatives – Just Alternative To

3 weeks ago
Golden Globes 2023: guarda i look delle star sul red carpet

Golden Globes 2023: guarda i look delle star sul red carpet

3 weeks ago

Popular News

    Connect with us

    Newsletter

    Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor.
    SUBSCRIBE

    Category

    • Business
    • Entertainment
    • Fashion
    • food
    • Games
    • Gaming
    • Health
    • Italy
    • Lifestyle
    • Movie
    • Music
    • National
    • News
    • Politics
    • Science
    • SPORTS
    • Tech
    • Technology
    • Travel
    • Uncategorized
    • WORLD

    Site Links

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    About Us

    We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

    • About
    • Advertise
    • Careers
    • Contact

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Create New Account!

    Fill the forms below to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In