Microsoft Excel is one of the most widely used programs. This makes it an attractive target for hackers. In fact, it was recently found that some of the legitimate features of the program itself can be even more helpful to hackers. In short, the program itself creates a problem for itself.

Researchers from Mimecast have discovered that an Excel feature called Power Querycan make it easier for hackers to carry out attacks on Office 365.Power Query allows users to combine data from various sources into a spreadsheet. However, this mechanism for connecting various elements can be used by hackers to connect to a malicious sitethat contains malware. In this way, attackers can spread malicious Excel spreadsheets and gain access to victims' systems.
“Attackers don’t need to carry out a very sophisticated attack. They can simply open Microsoft Excel and use its own tools,” says Meni Farjon, chief scientist at Mimecast. “The exploit will work in all versions of Excel, including new versions, and will likely work across all operating systems and programming languages because it relies on a legitimate feature.

When Power Query connects to a malicious site, attackers can launch a Dynamic Data Exchange attack, which exploits a Windows protocol that allows applications to share data across an operating system. Attackers can embed commands that enable DDE into their site and then use Power Query commands in a malicious spreadsheet to merge the site's data with that of the spreadsheet and launch the DDE attack.
Microsoft constantly warns users when they are about to link two programs, but hackers have been tricking victims with DDE attacks (on both Word documents and Excel sheets) since 2014.
In 2017, Microsoft advised users on how to avoid the attacks. It had suggested disabling DDE for various Office suite. However, the attacks continue. When researchers disclosed their findings about Power Query to Microsoft in June 2018, the company said it would not make any changes to the feature. Indeed, no changes have been made since. Farjon said his company waited until now to publicly disclose the findings, hoping that Microsoft would make some change. In the meantime, there has been no evidence that Power Query is being used in attacks. These attacks are difficult to detect because they come from a legitimate feature.

“Unfortunately, I think attackers will definitely use it,” says Farjon. “ It’s easy, exploitable, cheap and reliable.”
Meanwhile, last week, Microsoft informed its users that hackers are exploiting another Excel feature to compromise Windows machines, even those with the latest security updates. This attack, which appears to be targeting mainly Koreans, is triggered by malicious macros. This attack has been a major problem for Word and Excel for years.

Office 365 users want new, useful features, but every new feature can also be a new risk. The more capable and flexible the programs are, the more hackers can exploit them. Microsoft said that Windows Defender was able to block last week's macro attacks because it knew what to look for. But Mimecast's findings show that hackers are always finding ways to break into systems and infect them with malware.
Microsoft says that both malicious macros and Power Query can be controlled using an Office 365called “group policies.” This feature allows administrators to adjust settings across all devices in their organization at once.
