City
Epaper

Hackers now spreading malware via Microsoft OneNote attachments

By IANS | Published: January 22, 2023 2:33 PM

San Francisco, Jan 22 Hackers are now spreading malware using Microsoft OneNote attachments in phishing emails, infecting victims ...

Open in App

San Francisco, Jan 22 Hackers are now spreading malware using Microsoft OneNote attachments in phishing emails, infecting victims using remote access malware that can be used to install additional malware, steal passwords, or even cryptocurrency wallets.

For years, attackers have distributed malware in emails via malicious Word and Excel attachments that launch macros to download and install malware, reports Bleeping Computer.

However, in July last year, Microsoft disabled macros by default in Office documents, rendering this method untrustworthy for malware distribution.

Threat actors then quickly began using new file formats, such as ISO images and password-protected ZIP files, said the report.

These file formats quickly gained popularity, aided by a Windows bug that allowed ISOs to bypass security warnings and the popular 7-Zip (a free and open-source file archiver) utility's failure to propagate mark-of-the-web flags to files extracted from ZIP archives.

However, these bugs were fixed by both 7-Zip and Windows recently, preventing users from opening files in downloaded ISO and ZIP files without scary security warnings, the report added.

Microsoft OneNote is a free desktop digital notebook application that comes with Microsoft Office 2019 and Microsoft 365.

Meanwhile, the tech giant banned cryptocurrency mining from its online services to protect all of its cloud customers, media reports said.

"Cryptocurrency mining can disrupt or even impair Online Services and its users, and is often associated with unauthorised access to and use of customer accounts," Microsoft told The Register.

"We made this change to further protect our customers and mitigate the risk of disrupting or impairing services in the Microsoft Cloud," it added.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: microsoftBleeping computer
Open in App

Related Stories

NationalUnion Minister Ashwini Vaishnaw Urges Tech Giants Meta, Google, Amazon, and Microsoft to Take Responsibility Against Misinformation

Social Viral‘India, You Can Find Innovation Everywhere’: Bill Gates Shares Video With Nagpur Tea Seller ‘Dolly Chaiwalla’

TechnologyMicrosoft Cyber Attack: No Customer Data or Source Code Was Compromise, Says Company

BusinessEx-Microsoft CEO Steve Ballmer to receive 8300 crore from company for doing nothing

TechnologyMicrosoft joins OpenAI’s board, Sam Altman returns as CEO

Technology Realted Stories

TechnologyResearchers finds hidden threats with advanced x-ray imaging

TechnologyFinayo partners BYBY to provide financing options for customers buying e-rickshaws

Technology1st data from ESA's Euclid telescope offers snapshot of cosmic history

TechnologyUPI integration spurs growth in RuPay credit cards: Report

TechnologyMamaearth's parent firm Honasa logs Rs 30 crore PAT in Jan-March quarter