HomeSecurityHackers are using Microsoft OneNote attachments to spread malware

Hackers are using Microsoft OneNote attachments to spread malware

Threat actors are now using Microsoft OneNote attachments in phishing emails that infect victims with remote access malware, which can be used to install further malware, steal passwords or even cryptocurrency wallets.

See also: Roaming mantis Android malware upgraded

Microsoft OneNote malware

For years, hackers have been sending emails containing malicious Word and Excelthat launch macros to download and install malware. Now we're seeing a resurgence of this activity.

Last July, Microsoft disabled macros by default in Office documents – making malware distribution via this technique a thing of the past.

Before long, malicious actors began using new file formats, such as ISO images and password-protected ZIP archives. These documents quickly became ubiquitous due to a Windows glitch that allowed ISOs to bypass security warnings and the fact that the 7-Zip archive utility failed to propagate mark-of-the-web flags to files extracted from ZIP archives.

See also: Riot Games: Breach delays game fixes

Fortunately, both 7-Zip and Windows have recently fixed these bugs, thus eliminating the anxiety associated with security warnings when a user tries to open files from ISO and ZIP archives.

Hackers are using Microsoft OneNote attachments to spread malware

Undeterred by the change in technology, threat actors quickly adapted and began using Microsoft OneNote attachments as a malspam attachment fileformat.

Attachment Abuse in OneNote

Microsoft OneNote is a desktop digital notebook app! Easily accessible and free, this digital notebook app is pre-installed in Microsoft Office 2019 and Microsoft 365.

Anyone who has Microsoft Office/365 installed has immediate access to OneNote. The program is pre-installed, meaning users are able to quickly open and view all files saved in file format , without the need for any further downloads or installations.

Since mid-December, cybersecurity researchers have warned that threat actors have begun distributing malicious spam emails containing OneNote attachments.

As observed by BleepingComputer, these malicious spam messages are disguised as DHL shipping notifications, invoices, ACH transfer forms, mechanical diagrams, and shipping documents.

Hackers are using Microsoft OneNote attachments to spread malware

Unlike Word and Excel, OneNote does not support macros, which is how hackers previously launched scripts to install malware.

Instead of forcing you to open a separate document, OneNote gives users the ability to import attached files into their NoteBook, which can be opened with a simple double-click.

Hackers abuse this feature by attaching malicious VBS attachments that automatically launch the script when double-clicked to download malware from a remote website and install it.

See also: FanDuel: Warns of data breach after MailChimp hack

However, the attachments look like a file icon in OneNote, so threat actors overlay a large 'Double click to view file' line over the imported VBS attachments to hide them.

Microsoft OneNote

When you remove the “Click to View Document” line, you can see that the malicious attachment contains multiple attachments. With these attachments, the user can easily launch any attachment with a single double-click anywhere on the line.

Microsoft OneNote

Fortunately, OneNote takes the extra step of warning you before you open any attachments that could potentially put your computer and data at risk.

Unfortunately, we have found that these warnings are often ignored and users simply press the “OK” button.

Hackers are using Microsoft OneNote attachments to spread malware

Clicking the OK button will launch the VBS script to download and install malware. As you can see from one of the malicious OneNote VBS files detected by BleepingComputer, the script will download and execute two files from a remote server.

The first one shown below is a revealing OneNote document that opens and looks like the document you were expecting. However, the VBS file will also run a malicious batch file in the background to install malware on the device.

Microsoft OneNote

According to BleepingComputer's findings on malspam, OneNote files are being used to secretly install a remote access trojan with the ability to steal personal information.

James, a cybersecurity researcher, confirmed findings on BleepingComputer that OneNote attachments install the AsyncRAT and XWorm remote access trojans.

Beware of OneNote attachments – they may contain the malicious Quasar remote access Trojan! According to BleepingComputer, this trojan spreads via email attachments.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS