Payload Trends in Malicious OneNote Samples


In this post, Unt 42 researchers look at the types of embedded payloads that attackers leverage to abuse Microsoft OneNote files. Our analysis of roughly 6,000 malicious OneNote samples from WildFire reveals that these samples have a phishing-like theme where attackers use one or more images to lure people into clicking or interacting with OneNote files.

The interaction then executes an embedded malicious payload. Since macros have been disabled by default in Office, attackers have turned to leveraging other Microsoft products for embedding malicious payloads. As a result, malicious OneNote files have grown in popularity.

Read more…
Source: Palo Alto Unit 42


Sign up for our Newsletter


Related:

  • FBI: Whaling now a US$ 5 billion business as execs targeted

    May 9, 2017

    The US Federal Bureau of Investigation (FBI) has reported the continuing explosion of Business Email Compromise (BEC) attacks as the practice becomes a US$ 5 billion (£3.86 billion) business. Between October 2013 and 2016 the total international reported loss from such scams is US$ 5,302,890,449 (£4,100 million), with US bodies taking up nearly US$ 1.6 billion ...

  • Don’t click that Google Docs link! Gmail hijack mail spreads like wildfire

    May 3, 2017

    If you get an email today sharing a Google Docs file with you, don’t click it – you may accidentally hand over your Gmail inbox and your contacts to a mystery attacker. The phishing campaign really kicked off in a big way on Wednesday morning, US West Coast time. The malicious email contains what appears to ...

  • Fake Delta Airline Receipts Spread Financial Malware

    April 24, 2017

    Spam emails posing as Delta Air payment confirmation emails are spreading financial and banking malware to computers. According to Heimdal Security firm, a new campaign trying to get access to your financial information was noticed in the wild. Users are receiving spam emails posing as payment confirmations from Delta Air. As the researchers point out, this is ...

  • This Phishing Attack is Almost Impossible to Detect On Chrome, Firefox and Opera

    April 17, 2017

    A Chinese infosec researcher has discovered a new “almost impossible to detect” phishing attack that can be used to trick even the most careful users on the Internet. He warned, Hackers can use a known vulnerability in the Chrome, Firefox and Opera web browsers to display their fake domain names as the websites of legitimate services, ...

  • Personalized spam campaign targets Germany

    March 20, 2017

    A spam campaign Symantec observed in January 2017 targeting people who live in Germany appears to be, once again, using detailed, real personal information to enhance the believability of the messages. Victims who open the message attachments are likely to have their Windows computers infected with malware that steals banking information. First seen in the UK Symantec ...

  • Government Cybersecurity Contractor Hit in W-2 Phishing Scam

    March 17, 2017

    Just a friendly reminder that phishing scams which spoof the boss and request W-2 tax data on employees are intensifying as tax time nears. The latest victim shows that even cybersecurity experts can fall prey to these increasingly sophisticated attacks. On Thursday, March 16, the CEO of Defense Point Security, LLC — a Virginia company that ...