HomeSecurityWord security flaw exploited to carry out attacks on government websites...

Word security flaw exploited to launch attacks on Taiwanese government websites

Cybercriminals-Use-Microsoft-Word-Flaw-in-Attacks-Targeted-At-Taiwanese-Government

Last March, Microsoft issued a security advisory regarding a critical security flaw in Word, which allowed remote code execution and was being exploited by cybercriminals to carry out targeted attacks.

The company patched the security flaw in April, but experts are finding that cybercriminals are still relying on it for their campaigns.

According to Trend Micro, the Word vulnerability has been exploited in targeted attacks against Taiwanese government organizations and educational institutions.

The attacks against government agencies were based on emails purporting to come from a government official and containing malicious attachments.

Experts believe the attacks are part of the Taidoor campaign, which has been taking place since 2009.

Cybercriminals also appear to have exploited this vulnerability to launch a hacking attack against a popular Taiwanese email service. In this attack, the criminals relied on the PlugX RAT to steal files and take control of infected computers.

For more technical details about the attacks check out Trend Micro's blog.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS