Malicious hackers are exploiting Microsoft OneNote files as a means to compromise systems across various industries.
See also: A new Emotet phishing campaign targets US taxpayers

The campaign, under the radar of cybersecurity, highlights a new trend in cyberthreats, exploiting popular office applications to gain unauthorized access to corporate networks.
The malicious scheme was originally documented by pr0xylife on their GitHub repository . According to researchers from THE DFIR REPORT , a widespread email phishing operation has been discovered targeting companies in the manufacturing, technology, energy, retail, insurance, and many other sectors
The emails sent by the hackers contained Microsoft OneNote file attachments that claimed to be “secure messages,” to trick recipients into opening the files.
Proofpoint’s threat analysis highlighted the relatively low volume of the campaign, with researchers reporting that fewer than a thousand messages were observed over two days. However, the widespread attack on unrelated industries underscores the perpetrators’ intent to cast a wide net, hoping to catch unsuspecting victims.
The attack begins with the victim receiving an email containing a OneNote file. When opened, this file presents a large “Open” button behind which lies a Windows batch file named “Open.cmd.”
See also: Evernote: Is it eliminating its free plan?
Once executed, this file uses PowerShell to download an IcedID DLL that pretends to be a JPG file . This DLL then connects to command-and-control servers, signaling a successful system compromise

The simplicity of the initial access vector, combined with the use of a non-extremely advanced Microsoft OneNote file, indicates the hackers' reliance on social engineering rather than technical expertise to penetrate corporate networks.
The attack doesn’t stop at the initial breach. On the 33rd day of the attack, the IcedID facilitated the execution of Cobalt Strike beacons, a testament to the attackers’ patience and persistence.
Cobalt Strike, a legitimate tool used by cybersecurity professionals, has been abused by hackers for malicious purposes, allowing them to maintain a presence on the compromised network.
The campaign also demonstrated a way to achieve persistent presence by creating scheduled tasks and installing AnyDesk, a remote desktop software. This allowed the attackers to return to the compromised system at will, further strengthening their presence on the victim's network.
See also: Microsoft offers Office for free to 4 million users
How can we protect ourselves from cyberattacks?
Protecting against cyberattacks, such as those carried out by hackers through Microsoft OneNote files, requires a multi-layered approach. First, it is important to keep our device software and operating system up to date. Second, using strong, unique passwords and changing them frequently can make it difficult for cyberattackers to crack them. Also, using a password manager can help maintain and organize secure passwords. Third, training in recognizing and avoiding phishing attacks is crucial. These attacks are a common method used by cyberattackers to gain access to sensitive information. Finally, using antivirus protection, as well as creating regular data backups, can provide additional layers of protection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: gbhackers
