HomeSecurityEmotet malware: Distributed in Microsoft OneNote files

Emotet malware: Distributed in Microsoft OneNote files

The Emotet malware is delivered using email attachments via Microsoft OneNote, aiming to bypass Microsoft's security restrictions and infect victims.

Emotet malware: Moved to OneNote

Emotet is a malicious botnet that was previously distributed via Microsoft Word and Excel attachments that contained malicious macros. If a user opened the attachment and enabled the macros, a DLL would be downloaded and initiate an installation of the Emotet malware on the device.

Once the malware is loaded, it will begin stealing email contacts and content for use in future spam. It will also download additional payloads that will be used to provide access to the company’s network. This access is used for cyberattacks on companies, including ransomware attacks, data theft, cyber espionage, and blackmail.

See also: Winter Vivern hackers use fake antivirus scanners to distribute malware

After 3 months of inactivity, the Emotet botnet suddenly appeared through malicious emails internationally.

However, their initial campaign was not successful due to the continued use of macros in Word and Excel, resulting in Microsoft taking action and blocking macros in all attachment formats in these services.

Emotet malware: Distributed in Microsoft OneNote files

The switch to Microsoft OneNote

In an Emotet campaign first discovered by security researcher Abel, hackers began spreading the malware using Microsoft OneNote attachments.

These attachments are transferred via reply-chain emails that pose as guides, how-tos, invoices, work reports, etc.

Microsoft email

There are Microsoft OneNote files attached to the email that display a message that the file is protected. It then gives you the option to click View to display the file normally.

Microsoft OneNote

Microsoft OneNote allows you to create files that contain drawings that overlay an embedded document. However, even if the document is covered, wherever it is, it will start running the moment you click where it is.

Emotet malware: Distributed in Microsoft OneNote files

Suggestion: QakNote: Distribution of QBot malware via Microsoft OneNote files

The following VBScript includes a heavy, obscure script that downloads DLLs remotely, possibly from a compromised website, and then executes them.

Emotet malware: Distributed in Microsoft OneNote files

Although Microsoft OneNote will display a warning window when the user tries to open the embedded file, history shows that many users click OK to get rid of the notification.

Emotet malware: Distributed in Microsoft OneNote files

So if users click OK the embedded click.wsf VBScript file will be executed using WScript.exe from the OneNote temp folder, which is different for each user.

"%Temp%\OneNote\16.0\Exported\{E2124F1B-FFEA-4F6E-AD1C-F70780DF3667}\NT\0\click.wsf"

The script will then download the Emotet malware as a DLL and save it to the temp folder. It will then execute the randomly named DLL using regsvr32.exe.

Emotet will then begin stealing data while waiting for further commands from the command and control server. While it is not known what payloads it ultimately drops, they are typically used to install Cobalt Strike or other malware. These payloads are also used to gain access to the device and spread the malware across the network.  

Blocking malicious Microsoft OneNote files

Due to the recent surge in malicious files, Microsoft will be adding additional protection to OneNote against phishing files, but there is no specific timeline for when it will be available to everyone. However, Windows users can still use group policies to help combat malicious Microsoft OneNote files. Administrators can use them to block embedded files entirely or to block only specific file extensions

Microsoft OneNote

Read also: Use of Microsoft OneNote documents to deliver malware is increasing

It is crucial that administrators take advantage of these policies for additional security in OneNote.

source of information: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS