Security News

Microsoft Outlook Users Targeted By Gamaredon’s New VBA Macro
2020-06-11 20:37

The VBA macro leverages compromised victims' Microsoft Outlook email accounts to send spear-phishing emails to their contacts - rapidly widening the potential attack surface. Researchers say, while abusing a compromised mailbox to send malicious emails is not a new technique, this is the first publicly documented case of an attack group using both an Outlook macro and an OTM file to do so.

Researchers Dive Into Evolution of Malicious Excel 4.0 Macros
2020-06-04 04:15

For more than five months, Lastline security researchers have tracked the evolution of malicious Excel 4.0 macros, observing the fast pace at which malware authors change them to stay ahead of security tools. A central part of many organizations' productivity tools, Excel opens the door for phishing attacks where victims are tricked into enabling macros in malicious documents, which can results in the attackers gaining a foothold on the network, in preparation for additional activities.

Hackers Update Age-Old Excel 4.0 Macro Attack
2020-04-17 14:33

Hackers have updated the age-old Excel malware attack technique with a new passwordless twist. Researchers from security firm Trustwave said they discovered a new malspam campaign that sends Excel 4.0 xls 97-2003 files with a compromised macro in email messages.

Nigerian spammer made 3X average national salary firehosing macro-laden Word docs at world+dog
2020-03-17 13:38

A most entertaining piece of threat research from Check Point gives a unique insight into the "Working" life of a Nigerian email spammer who made thousands of dollars from stolen credit cards alone in recent years. Behind that facade of respectability, "Dton" was in fact an email spammer - a spammer working as part of a Nigerian cybercrime syndicate that generates its ill-gotten gains through buying and using stolen credit card details.

The Malicious Macros Problem May Be Solved Soon
2019-11-06 14:04

Using Containers, Malicious Documents Will Be Isolated in Office 365A handful of common lures still have astounding success in compromising computers: phishing emails, malicious links and the king...

PSA: Turning off silent macros in Office for Mac leaves users wide open to silent macro attacks
2019-11-05 06:08

Microsoft seems a bit hazy on what 'disable' actually means A security hole in Office for Mac can be exploited by miscreants to potentially run malicious code on victims' shiny computers without...

Microsoft Office for Mac Users Exposed to Macro-Based Attacks
2019-11-04 14:23

Microsoft Office for Mac does not properly disable XLM macros, thus exposing users to code execution attacks, the CERT Coordination Center (CERT/CC) at Carnegie Mellon University warns. read more

Fix LibreOffice now to thwart silent macro viruses – and here's how to pwn those who haven't
2019-07-30 18:28

Remove LibreLogo now Updated Update: See our note below: LibreOffice version 6.2.5, which was supposed to patch the macro security hole, is still vulnerable, and exploit code is now available....

Update LibreOffice now to thwart silent macro viruses – and here's how pwn those who haven't patched their suite yet
2019-07-30 18:28

Vulnerable version still on main download page, use 6.2.5 instead The Document Foundation has recently patched LibreOffice, its open-source office suite, to fix an issue where documents can be...

Author of Dryad and Rubella Macro Builders Arrested
2019-07-19 16:45

Dutch authorities this week announced the arrest a 20-year old man for allegedly developing and distributing Office Macro Builders.  read more