PoC Attack Leverages Microsoft Office and YouTube to Deliver Malware
#1
Quote:A stealthy malware delivery tactic has been uncovered in the way videos are embedded into Microsoft Word Documents, according to researchers. It allows JavaScript code-execution when a user clicks on a weaponized YouTube video thumbnail within a Word document – with no alert message displayed by Microsoft Office requesting user consent.

Researchers at Cymulate built a proof-of-concept attack using a YouTube video link and a Word document (although it’s possible to embed other kinds of video into Word, the researchers didn’t test those vectors, nor did it try this with other Office applications).

Word’s video-embedding feature creates an HTML script behind the video image, which is executed by Internet Explorer when the thumbnail inside the document is clicked.
According to a Cymulate analysis posted on Thursday, the team found that it’s possible to edit that HTML code to point to malware instead of the real YouTube video.

Source: https://threatpost.com/poc-attack-levera...re/138585/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
XYplorer
What's new in Rele...Kool — 13:23
QOwnNotes
26.3.14  Remember...Kool — 13:19
Opera 129
Dear Opera Users! ...harlan4096 — 11:05
Vivaldi 7.9 Build 3970.39
Vivaldi 7.9 Build ...harlan4096 — 11:04
Google Chrome 146.0.7680.153/154
Google Chrome 146....harlan4096 — 11:03

[-]
Birthdays
Today's Birthdays
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (38)Charlesfibre
avatar (43)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>