Security 12. July 2016

Federal government warns about harmful Office documents in e-mails attachments

The Reporting and Analysis Center for Information Assurance (MELANI) published a warning about malicious Office documents in mail attachments last Friday. The number of spam campaigns with malicious Microsoft Office documents has increased rapidly in recent weeks. Spam campaigns aimed at infecting computers with malicious software (malware) are now being observed on an almost daily basis.

The malware that is spread via this attack vector is usually Locky (ransomware) or Dridex (eBanking Trojan). While Locky malware encrypts files on the victim’s computer and then extorts the victims, Dridex targets the eBanking accounts of Swiss Internet users. Currently, customers of several Swiss banks are targeted by Dridex.

In each case, the attacks are carried out via so-called macros. Microsoft has therefore disabled the execution of unsigned macros by default. Now the attackers are trying to convince the recipients of the e-mails to activate macros. MELANIE advises never to execute macros in Office documents sent via e-mail.

How can you additionally protect yourself from attacks by malicious Office documents? MELANI provides recommendations on this. Customers of the Swiss Business Cloud from Open Circle are already protected in some respects.

What is covered by the Swiss Business Cloud?

  • As a Open Circle customer, your virus protection is always up to date. You are thus protected against malware in the best possible way.
  • Open Circle regularly creates a backup of your data. You could fall back on this in case of emergency.
  • Potentially harmful e-mail attachments are already blocked and filtered on your e-mail gateway or by the spam filter.
  • All e-mail attachments that contain macros (e.g. Word, Excel or PowerPoint attachments that contain macros) are blocked.

Without up-to-date virus protection and regular backups, malware attacks can have severe consequences. In the Swiss Business Cloud from Open Circle, your business data is protected in the best possible way. The firewall & network solution can also increase your security level.

What can you do yourself against malicious Office documents?

  • Be careful when handling Office documents. Do not open Office documents from unknown or suspicious senders; if in doubt, ask the sender by phone.
  • In general, be skeptical of unexpected e-mails (e.g. invoices, orders, etc.) or e-mails from unknown senders. If in doubt, contact the sender by telephone.
  • Use a collective signature for the authorization of payments via eBanking (each payment must thus be approved by two different eBanking contracts or logins, which massively reduces the risk of fraudulent payments).
  • Use a dedicated computer for eBanking, which you use exclusively for eBanking (no surfing, no reading of e-mails, etc.).

Further information

Source: MELANI 

Das könnte dich auch interessieren

Federal government warns against fraudulent calls to companies

Security 12. July 2018 Read the original notification of the Reporting and Analysis Center for Information Assurance of the Swiss Confederation. We recommend that you check the notification from the Confederation and take action if necessary: 1. Check what information about … Mehr erfahren
blank

Federal government warns against sextortion

Security 4. January 2019 Blackmailers claim in an email that they have access to computers and the webcam and threaten, if no ransom is paid, to send personal pictures and videos with sexual content to all contacts. As a … Mehr erfahren
blank

Federal government warns of forged FOPH e-mails

Security 18. March 2020 Since Friday afternoon (13 March 2020), cyber criminals have been trying to exploit the uncertainty of the population due to the current situation surrounding the corona virus. As sender of the mails, cybercriminals use the … Mehr erfahren
blank

Flubot – Malware via SMS

Security 1. July 2021 If you click on the link contained in the SMS message, you will be redirected to a fraudulent website where you are supposed to download the alleged voicemail. If you do so, you install the malware … Mehr erfahren
blank

Backup Methods for Your Business

Security, Solutions 2. November 2023 In the digital era, data is the backbone of any business. Data loss can be catastrophic - from business interruption to significant financial loss. Whether it's human or technical error, environmental impact, or a ransomware … Mehr erfahren
blank

Password manager – manage passwords securely

Security, Solutions 20. November 2023 What is a password manager and why should you use it? A password manager is a piece of software that helps us manage our passwords. It is used to store our passwords centrally in one place … Mehr erfahren

Open Circle AG
Freilagerstrasse 32
CH-8047 Zürich

©2024 Open Circle AG, all rights reserved.