HomeSecurityThe return of Macro Malware!

The return of Macro Malware!

The return of Macro Malware!
The return of Macro Malware and fileless malware

 

Security company Intel Security (formerly known as McAfee) has released an interesting report on the landscape of modern online threats, highlighting the most aggressive and widespread types of malware that have targeted users in the last month.

According to the researchers, two main types of malicious campaigns have been detected: the first relies on the use of macro-malware, and the second on the use of fileless, in-memory, malware.

The dynamic comeback of Macro Malware

Macro malware is classified as legacy malware and first appeared in the 1990s.

[alert variation=”alert-info”]“Macro” is a term used to describe a set of predefined functions that can be triggered by the press of a button. Many popular applications such as Microsoft Word and Microsoft Outlook allow the integration of macros, giving users the ability to perform repetitive tasks in an automated manner.

A macro virus – or "document virus" – is a virus written in a macro language that is embedded in files, and when these are opened, the virus is automatically executed, infecting systems.[/alert]
Macros are commonly used in software aimed at businesses, while in recent years, the wider interaction of macros with low-level computer features has become possible.

Because of this, macro-based malware has come back to the fore, most often spreading through infected Word documents.

These documents are delivered to victims via spear phishing or spam campaigns, and upon opening them, users are prompted to enable macro support. Once this happens, the malware automatically executes, putting users' computers at risk.

According to Intel Security, macro-based threats are at their highest level of prevalence in the past six years.

Fileless malware also in the spotlight

At the same time, an upward trend has been recorded in the spread of fileless malware (software that runs in the RAM of computers), which seem to have evolved significantly and are now truly fileless, in every sense of the word.

And while in-memory malware has been around for years, just like macro-malware, in the past it was not entirely fileless, always leaving a binary somewhere on the hard drive that was easily detectable by antivirus solutions.

According to Intel Security, the latest fileless malware versions, however, appear to have become much more powerful and are now harder to detect, as they operate entirely in the computer's RAM.

Among the most recent fileless threats that have been observed are malware families such as Kovter, Powelike, and XswKit.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS