sb-au logo
Story image

Attackers exploit macro-less Office documents to create havoc

03 Apr 2018

Cybercriminals use Microsoft Office documents to conduct ‘macro-less’ attacks that dodge organisations’ defences and inject malware – a technique that has been named a top threat in WatchGuard Technologies’ Q4 2017 Internet Security Report.

The report says that Dynamic Data Exchange (DDE) attacks are now on WatchGuard’s top 10 malware list, as hackers increasingly exploited issues within the Microsoft Office standard to execute code.

The DDE protocol is used to transfer data between applications – for example, Word may use the protocol to keep a table created in Excel up to date by automatically updating the information between the two programs, the report explains.

DDE attacks are also known as ‘macro-less’ malware. The attacks are able to use PowerShell and hidden scripts to dodge network defences.

Criminals have been quick to put these exploits into practice – two of the top 10 network attacks in Q4 involved Microsoft Office exploits.

The first top 10 network attack is a memory corruption vulnerability in Microsoft Office (CVE-2015-1650), which allows attackers to execute malicious code to install malware.

The second memory corruption vulnerability (CVE-2016-7231) is a similar attack that goes after Excel document.

“However, though the flaw lies in Excel, attackers can apparently exploit it using almost any type of Office document, including Word documents, Excel spreadsheets, or even PowerPoint presentations. Basically, if an attacker tricks you into opening a maliciously crafted Office document, they could exploit this to install malware on your system, with your privileges,” the report says.

Trojan.Downloader.DDE.Gen also uses Office documents and DDE threats in email campaigns. In one case, the Trojan delivered the Locky ransomware through a fake invoice document.

Malicious Office documents generally targeted Germany, China and the United States, and there was a large increase in malicious documents during Q4, the report notes.

“Although these criminal tactics may vary over time, we can be certain that this broad trend will persist, so the risks have never been greater for small and midsize organisations with less IT and security resources,” comments WatchGuard Technologies chief technology officer Cory Nachreiner.

Beyond the world of DDE threats, malware attacks grew significantly across the world. WatchGuard Fireboxes blocked more than 30 million malware variants in Q4 – a 33% increase over Q3. Zero-day malware threats grew most and accounted for 46% of all malware in Q4.

Cybercriminals are looking to EMEA as a lucrative target as the region accounted for 45.5% of the top malware attacks; followed by the Americas (40.5%) and Asia Pacific (14.1%).

The report says that malware attacks in Asia Pacific were relatively high compared to previous quarters, with Windows malware Win32/Heur taking out the top malware spot in the region.

“We encourage businesses of all sizes to proactively mitigate these threats with layered security services, advanced malware protection, and employee education and training in security best practices,” Nachreiner concludes.

Story image
Report: Rushing into cloud migration directly related to security issues
A new report from Radware highlights the impact of COVID-19 on organisations compelled to digitally transform in order to maintain business continuity. More
Story image
Phishing scam imitates SharePoint & OneNote for nefarious clicks
Sophos researchers say that the attackers take a slightly different approach to the standard ‘fake login’ phishing email.More
Story image
CrowdStrike integrates with ServiceNow program to bolster incident response
As part of the move, users can now integrate device data from the CrowdStrike Falcon platform into their incident response process, allowing for the improvement of both the security and IT operation outcomes.More
Story image
High-tech heist: why fending off ransomware attacks is more challenging than ever in 2020
The COVID-19 crisis has unleashed a wave of sophisticated and disruptive ransomware attacks, and the onus is on businesses to ramp up their security measures if they’re to avoid falling victim, writes Attivo Networks regional director for A/NZ Jim Cook.More
Link image
How a metrics-driven mindset can enable DevOps at enterprise scale
Here's how to enable dev teams to deploy higher-quality software and create reporting standards that clearly communicate software performance.More
Story image
Video: 10 Minute IT Jams - The benefits of converged cloud security
Today, Techday speaks to Forcepoint senior sales engineer and solutions architect Matthew Bant, who discusses the benefits of a converged cloud security model, and the pandemic's role in complicating the security stack in organisations around the world.More