Story image

Attackers exploit macro-less Office documents to create havoc

03 Apr 18

Cybercriminals use Microsoft Office documents to conduct ‘macro-less’ attacks that dodge organisations’ defences and inject malware – a technique that has been named a top threat in WatchGuard Technologies’ Q4 2017 Internet Security Report.

The report says that Dynamic Data Exchange (DDE) attacks are now on WatchGuard’s top 10 malware list, as hackers increasingly exploited issues within the Microsoft Office standard to execute code.

The DDE protocol is used to transfer data between applications – for example, Word may use the protocol to keep a table created in Excel up to date by automatically updating the information between the two programs, the report explains.

DDE attacks are also known as ‘macro-less’ malware. The attacks are able to use PowerShell and hidden scripts to dodge network defences.

Criminals have been quick to put these exploits into practice – two of the top 10 network attacks in Q4 involved Microsoft Office exploits.

The first top 10 network attack is a memory corruption vulnerability in Microsoft Office (CVE-2015-1650), which allows attackers to execute malicious code to install malware.

The second memory corruption vulnerability (CVE-2016-7231) is a similar attack that goes after Excel document.

“However, though the flaw lies in Excel, attackers can apparently exploit it using almost any type of Office document, including Word documents, Excel spreadsheets, or even PowerPoint presentations. Basically, if an attacker tricks you into opening a maliciously crafted Office document, they could exploit this to install malware on your system, with your privileges,” the report says.

Trojan.Downloader.DDE.Gen also uses Office documents and DDE threats in email campaigns. In one case, the Trojan delivered the Locky ransomware through a fake invoice document.

Malicious Office documents generally targeted Germany, China and the United States, and there was a large increase in malicious documents during Q4, the report notes.

“Although these criminal tactics may vary over time, we can be certain that this broad trend will persist, so the risks have never been greater for small and midsize organisations with less IT and security resources,” comments WatchGuard Technologies chief technology officer Cory Nachreiner.

Beyond the world of DDE threats, malware attacks grew significantly across the world. WatchGuard Fireboxes blocked more than 30 million malware variants in Q4 – a 33% increase over Q3. Zero-day malware threats grew most and accounted for 46% of all malware in Q4.

Cybercriminals are looking to EMEA as a lucrative target as the region accounted for 45.5% of the top malware attacks; followed by the Americas (40.5%) and Asia Pacific (14.1%).

The report says that malware attacks in Asia Pacific were relatively high compared to previous quarters, with Windows malware Win32/Heur taking out the top malware spot in the region.

“We encourage businesses of all sizes to proactively mitigate these threats with layered security services, advanced malware protection, and employee education and training in security best practices,” Nachreiner concludes.

Using blockchain to ensure regulatory compliance
“Data privacy regulations such as the GDPR require you to put better safeguards in place to protect customer data, and to prove you’ve done it."
A10 aims to secure Kubernetes container environments
The solution aims to provide teams deploying microservices applications with an automated way to integrate enterprise-grade security with comprehensive application visibility and analytics.
DigiCert conquers Google's distrust of Symantec certs
“This could have been an extremely disruptive event to online commerce," comments DigiCert CEO John Merrill. 
One Identity a Visionary in Magic Quad for PAM
One Identity was recognised in the Gartner Magic Quadrant for Privileged Access Management for completeness of vision and ability to execute.
Gartner names newcomer Exabeam a leader in SIEM
The vendor landscape for SIEM is evolving, with recent entrants bringing technologies optimised for analytics use cases.
52mil users affected by Google+’s second data breach
Google+ APIs will be shut down within the next 90 days, and the consumer platform will be disabled in April 2019 instead of August 2019 as originally planned.
Symantec releases neural network-integrated USB scanning station
Symantec Industrial Control System Protection Neural helps defend against USB-borne cyber attacks on operational technology.
Ramping up security with next-gen firewalls
The classic firewall lacked the ability to distinguish between different kinds of web traffic.