惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
博客园 - 【当耐特】
月光博客
月光博客
Vercel News
Vercel News
D
Docker
I
InfoQ
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
雷峰网
雷峰网
博客园 - 聂微东
小众软件
小众软件
Y
Y Combinator Blog
腾讯CDC
L
LangChain Blog
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Microsoft OneNote Malware Delivery and Installation
Intel 471 · 2023-03-29 · via Intel 471 Blog

Threat Summary

OneNote is a digital note-taking application developed by Microsoft. It allows users to create and organize notes in various formats, including text, images, audio recordings, and video. OneNote files have become a popular alternative to macro-based files, like Word documents, which have become more difficult to distribute due to Microsoft's patching of vulnerabilities and disabling of macros. OneNote files have been observed containing embedded files, such as HTA, CMD, and JSE binaries, which are used to execute malicious code when the OneNote file is opened.

Phishing campaigns have been observed delivering OneNote files containing malicious files via email or malicious URLs. Once the OneNote file is opened and the embedded file is executed, it downloads a second-stage payload from the attacker's infrastructure. Recent variants have been observed dropping Emotet and QakBot, which is commonly used to deliver additional payloads such as Cobalt Strike.

It is recommended to use the most recent patches for Microsoft Windows on computers and endpoints, and to avoid opening unknown attachments or visiting unfamiliar URLs. Password security is also important, and switching to two-factor authentication can provide an additional layer of protection. Due to the usage of OneNote in many Microsoft Windows systems and the ubiquity of Microsoft Office globally, as well as the ongoing comprehension and understanding of the ability to abuse OneNote, it is important that organizations prepare themselves and stay on top of any updates concerning malicious use of Microsoft OneNote.

Threat Synopsis - Microsoft OneNote Malware Delivery and Installation

With the efforts by Microsoft to block Excel 4 and VBA macros that are downloaded from the internet by default, threat actors have taken to using Microsoft OneNote to deliver malicious payloads to unsuspecting victims. Among the actors and malware campaigns taking advantage of this technique, Emotet and Qakbot have been some of the most prevalent. These new email campaigns have been using malicious Microsoft OneNote attachments to distribute malware, with the attachments often disguised as guides, invoices, job references, and other types of documents.

The OneNote documents display a message that the document is protected and prompt the user to double-click the "View" button to display it properly. However, actors have been hiding various script files underneath the "View" button, which downloads a DLL or other payload from a remote location and executes it. This leads to the installation of Emotet and other malware, which can steal email, contacts, and await further commands from the command and control server.

While Microsoft OneNote displays a warning when attempting to launch an embedded file, users often click "OK" to get rid of the alert, enabling the malicious script to execute. Microsoft is adding improved protections in OneNote against phishing documents, but there is no specific timeline for when this will be available to everyone. However, Windows admins can configure group policies to protect against malicious OneNote files by either blocking embedded files altogether or specifying specific file extensions to be blocked from running.

Due to this Microsoft OneNote method being a relatively new, and with additional information about the threat actors using it and the methods of which they use it being discovered, Cyborg Security will be updating the Threat Hunt Packages as more information is identified.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >