Geeks for your information
Evil Clippy Makes Malicious Office Docs that Dodge Detection - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Evil Clippy Makes Malicious Office Docs that Dodge Detection (/showthread.php?tid=6911)



Evil Clippy Makes Malicious Office Docs that Dodge Detection - Mohammad.Poorya - 07 May 19

Quote:Security researchers brought to life and released a wicked variant of Clippy, the recently resurfaced assistant in Microsoft Office that we all loved so much to hate, that makes it more difficult to detect a malicious macro in documents.

Dubbed Evil Clippy, the tool modifies Office documents at file format level to spew out malicious versions that get by the static analysis of antivirus engines and even utilities for manual inspection of macro scripts.

To do this, it takes advantage of undocumented features, unclear specifications, and deviations from intended implementations.

Macros are snippets of VBA (Visual Basic for Applications) code that automate tasks in Microsoft Office applications. They are constantly used to deliver malware when the user opens a document.

SOURCE