GearriceGearrice
  • Tech World
  • Smart Home
  • Mobile Zone
  • 5G
  • Alexa
  • Amazon
  • AMD
  • Android
  • Apple
  • AirPods
  • AirTag
  • Apple Studio
  • Apple TV
  • Apple Watch
  • HomePod
  • iOS
  • iOS 15.4
  • iPad
  • iPhone
  • Mac
  • iMac
  • MacBook
  • Apps
  • Asus
  • Bitcoin
  • Cars
  • ChatGPT
  • Computer
  • Keyboard
  • Contact us
  • Disney
  • Display
  • Electric
  • Elon Musk
  • Gaming
  • Google
  • Chromecast
  • Google Maps
  • HBO
  • How to
  • Huawei
  • HONOR
  • Instagram
  • Intel
  • Internet
  • iQOO
  • Laptop
  • Lenovo
  • LG
  • Meta
  • Facebook
  • Galaxy
  • Metaverse
  • Microsoft
  • Windows
  • Motorola
  • Movies
  • Movistar
  • MWC Barcelona 2022
  • Netflix
  • News
  • Nintendo
  • Nokia
  • Nvidia
  • OPPO
  • OnePlus
  • Realme
  • Orange
  • Oscars
  • Philips
  • PlayStation
  • Pokémon
  • Qualcomm
  • Snapdragon
  • Samsung
  • Solar
  • Sony
  • SpaceX
  • Spotify
  • Tablet
  • Tesla
  • TikTok
  • Tips and Tricks
  • Today
  • Twitch
  • Twitter
  • Vivo
  • VPN
  • WhatsApp
  • Write For Us
  • MIUI
  • POCO
  • Redmi
  • Mouse
  • OLED
  • Prime
  • Scooter
  • Xbox
  • Xiaomi
  • YouTube
Facebook Twitter Instagram
Facebook Twitter Instagram Pinterest
Gearrice Gearrice
Subscribe
  • Tech World
  • Best Deals
  • Gaming
  • Mobile Zone
    • Android
    • Apple
  • Smart Home
GearriceGearrice
Home»Mobile Zone»Android»Beware of these fake OneNote files used by hackers to steal your information

Beware of these fake OneNote files used by hackers to steal your information

By Elizabeth George10/02/20232 Mins Read
Share
Facebook Twitter LinkedIn Pinterest

A phishing campaign led by the Qakbot hacker group uses the malware of the same name to spread through the email inboxes of their victims.

A laptop screen displays a Malware! / Credit: 123rf

Sophos security researchers uncovered a phishing campaign using a malware called Qakbot. They send emails containing an attached file. The latter is a file in the format. one, which leads the recipient of the message to believe that someone they know wants to share a OneNote document. Once he clicks on the attached file, a OneNote page appears. It states: “This document contains attachments from the cloud. To receive them, double-click on Open”. If you click this button, trouble begins.

Fake QakBot OneNote document / Credit: Sophos

The executed HTML application will download Qakbot’s malicious code from a remote server and execute it on the victim’s computer. To go unnoticed by antivirus software, imported files pretend to be images (in png or gif format, for example). These are actually DLLs designed to execute malicious scripts and infect Windows system applications.

Qakbot inserts itself into email conversations and “reproduces” itself in this way

Sophos says, “If you’re not sure […] take the time to call or message the sender and make sure he actually sent you the document”. This is the best way to never be infected, unfortunately it is not always enough. Qakbot has the ability to insert messages in the middle of existing conversation threads. Researchers readily admit, he is very good at quoting a previous post and causing confusion with the participants.

To read – Phishing: hackers have found a new technique to trap you even better

Using OneNote files to infect Windows computers appears to be a very recent technique, since Sophos estimates that this campaign began on January 31, 2023. If the infection vector, Qakbot, is known, the company does not give more details on the nature of the abuses of the hacker group. Their malware can be used to steal user data, or to take possession of a PC to integrate it into a botnet.

Source: TechRadar

Related Posts

ChatGPT Saves Dog’s Life After Vet’s Misdiagnosis

Someone else can access your smartphone without your knowledge! Watch out for this!

How to Identify Free Telephone Numbers Online?

Add A Comment

Leave A Reply Cancel Reply

Tech World

The Tech That is Enabling Retailers to Thrive 

By gearrice01/04/20230

ChatGPT Saves Dog’s Life After Vet’s Misdiagnosis

01/04/2023

A 61-year-old man tries to sneak 510,000 processors, SSDs and mobiles through Chinese customs, all at the same time

01/04/2023

Someone else can access your smartphone without your knowledge! Watch out for this!

01/04/2023

The new Redmi Note 12 Pro 5G has just come out and already has its first discount

01/04/2023
Gearrice
Facebook Twitter Instagram Pinterest
  • Privacy Policy
  • Terms and Conditions
  • Write For Us
© 2023 Gearrice.

Type above and press Enter to search. Press Esc to cancel.