Hackers Are Now Using Microsoft OneNote Attachments To Distribute Malware: Report

Hackers Are Now Using Microsoft OneNote Attachments To Distribute Malware: Report

[ad_1]

Last Updated: January 23, 2023, 12:27 IST

Microsoft OneNote comes included with Microsoft Office.

Microsoft OneNote comes included with Microsoft Office.

As per a recent report, hackers are now using Microsoft OneNote to spread malware and steal passwords. Here are all the details.

Hackers are now spreading malware using Microsoft OneNote attachments in phishing emails, infecting victims using remote access malware that can be used to install additional malware, steal passwords, or even cryptocurrency wallets.

For years, attackers have distributed malware in emails via malicious Word and Excel attachments that launch macros to download and install malware, reports Bleeping Computer.

However, in July last year, Microsoft disabled macros by default in Office documents, rendering this method untrustworthy for malware distribution.

Threat actors then quickly began using new file formats, such as ISO images and password-protected ZIP files, said the report.

These file formats quickly gained popularity, aided by a Windows bug that allowed ISOs to bypass security warnings and the popular 7-Zip (a free and open-source file archiver) utility’s failure to propagate mark-of-the-web flags to files extracted from ZIP archives.

However, these bugs were fixed by both 7-Zip and Windows recently, preventing users from opening files in downloaded ISO and ZIP files without scary security warnings, the report added.

Microsoft OneNote is a free desktop digital notebook application that comes with Microsoft Office 2019 and Microsoft 365.

Meanwhile, the tech giant banned cryptocurrency mining from its online services to protect all of its cloud customers, media reports said.

“Cryptocurrency mining can disrupt or even impair Online Services and its users, and is often associated with unauthorised access to and use of customer accounts,” Microsoft told The Register.

“We made this change to further protect our customers and mitigate the risk of disrupting or impairing services in the Microsoft Cloud,” it added.

Read all the Latest Tech News here

(This story has not been edited by News18 staff and is published from a syndicated news agency feed)

[ad_2]

Source link

This Post Has 7 Comments

  1. binance Register

    Thanks for sharing. I read many of your blog posts, cool, your blog is very good. https://accounts.binance.com/bg/join?ref=V2H9AFPY

  2. ^Inregistrare pe Binance

    Your article helped me a lot, is there any more related content? Thanks! https://www.binance.com/en-IN/register?ref=UM6SMJM3

  3. Pendaftaran Binance

    Thanks for sharing. I read many of your blog posts, cool, your blog is very good.

  4. bonus di riferimento binance

    Can you be more specific about the content of your article? After reading it, I still have some doubts. Hope you can help me. https://www.binance.info/en-IN/register?ref=UM6SMJM3

    1. Er. Vishnu

      Thank you for going through the article and sharing your feedback! I completely understand—sometimes a topic may still leave questions even after reading. Could you please let me know which part you’d like more clarity on? I’ll be happy to explain in detail and, if needed, expand the article to make it more useful for you and other readers.

  5. binance create account

    Your article helped me a lot, is there any more related content? Thanks!

  6. binance US-registrera

    Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me? https://www.binance.com/sv/register?ref=IQY5TET4

Leave a Reply