In a new kind of attack, cybercriminals are infecting computers with a banking Trojan simply by fooling users into hovering over a link embedded in a malicious PowerPoint file.
Attackers are sending malicious PowerPoint Show (PPS) or Open XML Slide Show (PPSX) to users via spam emails. These files only open in slideshow modes and are different from the normal PowerPoint files (PPT and PPTX). When the targeted user downloads and opens such a file, a slide containing the below hyperlink gets displayed.
If the user hovers their mouse over this link, it tries to execute a code which installs a banking Trojan on the computer. Users who have the ‘Protected View‘ feature turned ON (newer versions of Windows), receive a security warning (fig 2) with ‘Enable’, ‘Enable All’, and ‘Disable’ options. Clicking on ‘Enable’ or ‘Enable All’ executes the malicious code which ultimately infects the computer with the Trojan. Clicking on ‘Disable’ will stop the infection from getting executed.
Therefore, users with older versions of Windows or those who do not have the ‘Protected View’ ON are the most vulnerable to this infection. Simply hovering over the link will have their computer infected without any notice.
Once installed, this banking Trojan can allow the attacker control the infected computer remotely, access stored information and perform a host of other malicious activities.
How Quick Heal helps
Quick Heal offers multilayered protection against this attack.
– Quick Heal detects this malware as JS.Nemucod.DSG.
– Quick Heal Web Security detects and blocks the malicious link which is responsible for downloading the malware.
– Quick Heal Virus Protection detects the malicious Slide Show (PPSX) file as OLE.PS.Downloader.2352
Security measures you must take
1) On receiving any security prompts, such as the one above, it is safer not to proceed. You can always consult a computer expert if you are not sure about what to do.
2) Never click on links or download attachments that come with unexpected, unwanted or unknown emails.
3) Install an antivirus software that offers layers of protection. This helps detects and blocks such threats on multiple levels. And keep the software up-to-date.
4) Apply all recommended security updates (patches) to your Operating System, programs like Adobe, Java, Internet Browsers, etc.
5) It is always a good security practice to keep a secure backup of your important data.
6) Use strong and unique passwords for your online accounts.
Subject Matter Expert
- Anita Ladkat | Quick Heal Security Labs