One of the most critical aspects of computer security is that malicious developers are never idle (and never have been). What seemed impossible a couple of years ago is now a new infection method, or the optimization of an existing one. The latest news comes from Trend Micro, which discovered a trojan capable of attacking with a special PowerPoint document containing a malicious link that doesn't need to be clicked. Simply passing the cursor over that link is enough.

New PowerPoint Trojan Strikes by Just Hovering Over a Link
PowerPoint

Why banking credentials keep attracting malware

Home banking and electronic fund management keep gaining ground, turning the end user into an increasingly tempting target for malicious developers looking to run more precise campaigns. Despite the enormous damage it caused, the WannaCry operators didn't even collect $75,000. In other words, it's too much attention for too little money. While we all know it's only a matter of time before the next big ransomware attack sets half the web on fire, it's not far-fetched to imagine a set of subtler, quieter campaigns in the meantime.

New PowerPoint Trojan Strikes by Just Hovering Over a Link
The trojan's distribution uses emails with a format similar to this

The hover-triggered trojan

One of those campaigns has just been uncovered by Trend Micro on European soil. The downloader, which the company detects under the names TROJ_POWHOV.A and P2KM_POWHOV.A, presents the user with a PowerPoint document loaded with an image or a linked piece of text. The most striking part is that the user doesn't need to click that link; just hovering over it triggers the installation (using a PowerShell command) of a banking trojan known as OTLARD or Gootkit. This trojan previously attacked in French territory a couple of years ago distributing judicial spam, and its ability to steal banking credentials is well documented.

New PowerPoint Trojan Strikes by Just Hovering Over a Link
Hovering over a link is almost instinctive...

How to defend against it

Trend Micro indicated that this new campaign was just a blip on its radar, with a limited number of infections over five days. However, that's not unusual (the plan is to reduce its footprint to make investigators' work harder), and the first impression is that it's a test flight. Now the question is: how do we defend ourselves? Trend Micro confirmed that the trojan does not work in PowerPoint Online, nor in the Office 365 web mode, but it can affect the rest. The first line of defense is to keep Protected View in Office enabled, and to apply a vote of no confidence to that content (an unknown email with a PowerPoint attachment is probably asking for trouble). Maybe Microsoft will release a general hotfix to minimize or completely nullify its impact, and I imagine security companies will make the corresponding adjustments to their products. We must stay alert.

For the official announcement from Trend Micro, visit the blog post.