Some attackers use Microsoft OneNote notes to spread malware and steal sensitive information.
CTOnews.com January 23 news, according to foreign science and technology media BleepingComputer reported that a malicious attacker used notes in OneNote to spread malicious files. The attacker sends a phishing email and contains files such as DHL invoices, remittance forms, shipping notices and files, and mechanical drawings.
An attacker appends a malicious VBS file to the OneNote note. Once the user double-clicks, these files are automatically downloaded and installed from the remote site. To hide them and make the OneNote documents look as legitimate as possible, the attacker overrides these files with a "double click to view the file" box.
This means that clicking the box will launch the malicious file, which will install the malicious software on the device. Although OneNote warns users that opening attachments may damage their computers and data, many users may ignore the warning and click OK.
CTOnews.com learned that malicious OneNote documents often install remote access Trojans that can steal sensitive information and cryptocurrency wallets. Attackers can even use the victim's webcam to take screenshots and record videos.