post-Profile

Pedro Ibanez

post-Profile
15 August, 2023 - 5 min read

Malicious documents are dead, long live malicious

After almost three decades of Microsoft Office macro malware being used to infect computers and a decade of it being one of the most common types of malware being distributed, Microsoft has dealt a potentially fatal blow by having all macros from downloaded files being disabled by default. That means no more message that can be clicked to simply enable the macro. Macros are completely blocked and require a great deal of user intervention to re-enable.

However, as the saying goes, "nature abhors a vacuum," and threat actors have spent years honing their social engineering playbook around document malware. Add to this the out-of-the-box thinking required to succeed in this line of work and cybercriminal history of trying novel approaches to evade malware detection and we get weaponized OneNote files being used to distribute Qakbot, likely the first of many new approaches to document malware.

How QuakNote malware campaign works

post-Profile

After almost three decades of Microsoft Office macro malware being used to infect computers and a decade of it being one of the most common types of malware being distributed, Microsoft has dealt a potentially fatal blow by having all macros from downloaded files being disabled by default. That means no more message that can be clicked to simply enable the macro. Macros are completely blocked and require a great deal of user intervention to re-enable.

However, as the saying goes, "nature abhors a vacuum," and threat actors have spent years honing their social engineering playbook around document malware. Add to this the out-of-the-box thinking required to succeed in this line of work and cybercriminal history of trying novel approaches to evade malware detection and we get weaponized OneNote files being used to distribute Qakbot, likely the first of many new approaches to document malware.

Related Articles

post-Profile
15 August, 2023 - 5 min read
Automating Security Operations...

Human actors still drive the vast majority of security breaches. In 2022, 82% of breaches involved the human element, whether...

post-Profile

Pedro Ibanez

post-Profile
15 August, 2023 - 5 min read
Malvertising makes a comeback

Malvertising is nothing new. But often times for hackers, what’s old is new again. Malvertising is nothing new. But often times...

post-Profile

Pedro Ibanez