New Infected Document Forces Word to Download Malware
Word

Even though Microsoft has introduced several protection mechanisms in the Office suite, infections through its main components (with Word and Excel at the top) have never completely disappeared. The teams at McAfee and FireEye reported this weekend a new zero-day vulnerability that apparently affects all versions of Word. The only thing an attacker needs to exploit this bug is an RTF document that forces Word to download an HTML application (.HTA), which in turn installs malware in the background.

How the attack works

The concept of the “Trojan horse” is one of the oldest when it comes to infecting a computer. The user thinks a file performs a certain function or has a specific format, and when they double-click… they find the surprise. Unfortunately, common sense has limits, because there is a possibility that the infected file arrives through a trusted contact, who has no idea about their involuntary participation in the distribution of malware. This is very common among users who depend on tools like the Office suite. A good part of the infections via Word and Excel require the activation of macros or another mechanism, but the last bug detected in circulation has proven to be much more robust.

New Infected Document Forces Word to Download Malware
This is how the attack hides itself

McAfee and FireEye reported over the weekend a new series of attacks involving an RTF document. The document contains an OLE object, and once opened, Word proceeds to download an HTML application (with .hta extension) from a remote server. From there, the .hta file executes its malicious script, and in an attempt to hide its actions, it presents the user with a fake document, as if nothing strange had happened. The most striking thing is that this attack manages to cross all existing protections (even if the user works on Windows 10), works on all versions of Word, and does not require the aforementioned macro activation.

Protection and recommendations

The FireEye team stayed in contact with Microsoft for several weeks, and they agreed not to publish data about the zero-day until the patch is ready, but McAfee beat them to it, indicating that the first attacks were recorded in late January. The ideal would be not to open documents that come to us from untrusted sources, but what McAfee and FireEye recommend (at least until the hotfix is applied) is to open the content using the Protected View feature.