Sophos X-Ops · @SophosXOps
1349 followers · 131 posts · Server infosec.exchange

Our coverage of this campaign includes a breakdown of the attack chain, IOCs, and some other curious details. People unfamiliar with OneNote as a weaponized document format should get used to this; are probably here to stay. 6/6

news.sophos.com/en-us/2023/02/

#onenote #maldoc #malware #qaknote #maldocs

Last updated 2 years ago

@SophosXOps
Our coverage of this campaign includes a breakdown of the attack chain, IOCs, and some other curious details -- such as the fact that the embedded graphic elements were originally added to the document using filenames in the Russian language. "Curious," that.

People unfamiliar with OneNote as a weaponized document format should get used to this; are probably here to stay -- at least, until mail server admins decide to block all inbound .one attachments. 6/6

news.sophos.com/en-us/qakbot-o

#malware #qaknote #maldocs

Last updated 2 years ago

MathieuB · @MathieuB
33 followers · 500 posts · Server mastodon.xyz