Skip to content
NVISO Labs

NVISO Labs

Cyber security research, straight from the lab! 🐀

  • twitter
  • linkedin
  • mail us
  • our company
  • SSO

Series: OneNote as a Malware delivery platform

OneNote can be used to deliver malware. This series will show how OneNote can be abused and how you can protect your environment against this attack technique

OneNote Embedded URL Abuse

Whilst Microsoft is fixing the embedded files feature in OneNote I decided to abuse a whole other feature. Embedded URLs. Turns out this is something they may also have to fix.

Nicholas Dhaeyer SOC, Threat Hunting, Blue Team, Qbot, OneNote, Cyber Threats, Maldoc, phishing, Malware 3 Comments March 27, 2023March 26, 2023 5 Minutes

OneNote Embedded file abuse

In recent weeks OneNote has gotten a lot of media attention as threat actors are abusing the embedded files feature in OneNote in their phishing campaigns. In this post we will analyze this new way of malware delivery and create a detection rule for it.

Nicholas Dhaeyer Cyber Threats, Maldoc, Malware, phishing, Reverse Engineering, Threat Hunting, Detection Engineering, Qbot, OneNote 4 Comments February 27, 2023March 12, 2023 8 Minutes
Powered by WordPress.com.