Get a Pentest and security assessment of your IT network.

News

Microsoft Word subDoc Feature Abused to Steal Windows Credentials

Security research team at Rhino Labs, a US-based cyber-security company, has discovered that malicious actors can use a lesser-known Microsoft Word feature called subDoc to trick Windows computers into handing over their NTLM credentials. Attackers can then use these logins to access the victim’s computer or network, posing as the original user. This type of hack is ideal for spear-phishing campaigns aimed at high-value targets, such as enterprises or government agencies. The fate of subDoc is unknown because this feature is not that useful for regular malware distribution campaigns.

Source: https://www.bleepingcomputer.com/news/security/microsoft-word-subdoc-feature-abused-to-steal-windows-credentials/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Vulnerabilities In Alibaba threatens security of million users

News

Russian cybercriminal Roman Seleznev gets another prison sentence