Attackers steal data using Word files

By: Anton Melnik | 18.02.2018, 19:45
Attackers steal data using Word files

As the company Trustwave SpiderLabs, hackers began to spread by e-mail a new virus under the guise of Word documents. Previously, this was already, but now the malicious program does not have any macros, which complicates its detection.

Principle of operation

Unlike the previous such virus, users do not open new windows and do not pop up warnings. Attackers collect data from the "lucky" browsers, who received an e-mail with a letter about finances with an attached document called "receipt.docx".
The researchers reported that the virus attacks were multilevel and compared them with turkaken - a festive dish of turkey, in which a duck is placed, and inside the duck is a chicken. The virus uses many stages and scripts, moreover, DOCX, RTF and HTA file formats are rarely blocked by anti-virus programs.
In order not to become a victim of burglars, it's enough to ignore messages from unknown senders and not open suspicious files - all as usual.

Source: threatpost