This attack uses mouse movement to launch malicious code in booby-trapped documents. Attack abuses the hyperlink feature to launch a Powershell command as soon as the user moves their mouse cursor over that link. Malwarebytes users were already protected against this threat thanks to our Application Behavior Protection: The fact that it does not need a macro is novel is novel and triggers on mouse activity is a clever move. There is no doubt threat actors will keep on coming up with various twists to abuse the human element.”]

