logo
Do Not Open This PDF On A Microsoft Windows PC

Do Not Open This PDF On A Microsoft Windows PC

Forbes04-05-2025
Do not open this PDF—delete on sight.
A few weeks on from Microsoft warning Windows users that PDF attachments are increasingly being used in attacks, there's another warning and a new lure. While the Windows-maker's alert for PC users came ahead of tax day in the U.S., the new attack is less time critical and has a nasty trick in how it masks its malicious intent.
Microsoft's tax day warning called out 'PDF attachments with an embedded DoubleClick URL that redirected users to a Rebrandly URL shortening link. That link in turn redirected the browser to a landing site that displayed a fake DocuSign page hosted on a domain masquerading as DocuSign.'
When users clicked to download, 'the outcome depended on whether their system and IP address were allowed to access the next stage based on filtering rules set up by the threat actor.' This was a clever form of obfuscation to make it more difficult for security researchers to replicate the attack and craft a fix.
Now, the team at TrustWave SpiderLabs warn 'we've spotted a campaign delivering RemcosRAT, using a fake payment SWIFT copy to lure victims. The attached PDF links to an obfuscated JavaScript file that uses ActiveXObject to fetch a second-stage script. This script invokes PowerShell to download and decode an image hosted on archive.org, which appears harmless but conceals the Remcos payload using steganography.'
Again, obfuscation here is key. The latest trickery in malicious PDFs is to hide links behind QR codes or to compile PDFs without the usual URL tag, making it harder to a security scan to pick up the treat. Steganography takes this to a new level, hiding the link in an image, and making it all but impossible for a user to detect.
As Kaspersky explains, 'steganography is the practice of concealing information within another message or physical object to avoid detection. Steganography can be used to hide virtually any type of digital content, including text, image, video, or audio content. That hidden data is then extracted at its destination. Content concealed through steganography is sometimes encrypted before being hidden within another file format. If it isn't encrypted, then it may be processed in some way to make it harder to detect.'
According to Cybersecurity News, the new attack 'begins with a phishing email that attaches a PDF file contains a malicious link, specifically pointing to malicious webpage: https://huadongarmouredcable.com/pdf/default.php… luring victims into a multi-stage infection process designed to deliver RemcosRAT, a malware known for its ability to remotely control infected systems.'
RemcosRAT is a nasty trojan you don't want anywhere near your PC. But the warning is not really that specific. PDFs are highlighted as a new favorite for cyber attacks, given user wariness as regards Office documents. The feeling amongst users seems to be that PDFs are more benign and therefore safer. Unfortunately, that's not the case.
As for what to look for here. An email headed 'SWIFT Copy' that purports to confirm a bank transfer with an attacked receipt. While for most this lure is typical of the raft of latest threats, these campaigns are hitting plenty of marks. That's why they proliferate.
Delete on sight.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

ROG Xbox Ally X Price Leaks, Thanks to Retailer in Spain
ROG Xbox Ally X Price Leaks, Thanks to Retailer in Spain

Yahoo

time4 hours ago

  • Yahoo

ROG Xbox Ally X Price Leaks, Thanks to Retailer in Spain

Microsoft is partnering with Asus to bring the Xbox to a handheld, Nintendo Switch-like console. That device, known as the Asus ROG Xbox Ally, will hit store shelves in time for the holidays this year. Thanks to a retailer in Spain, would-be buyers can get a sense of how much cash they'll be shelling out for the mobile gaming console. As VideoCardz notes, a retailer and distributor in Spain made a webpage public with prices ranging from €599 to €899. Leaving aside the prospect of possible changes in US pricing due to tariffs, that would put the ROG Xbox Ally in the neighborhood of $699 to $1,049. For comparison, the Asus ROG Ally ranges from $500 to $650, and Valve's Steam Deck ranges from $400 to $650. The Nintendo Switch 2, on the other hand, has an MSRP of $450, though anyone who plays Mario Kart would do well to get the $500 console/game bundle for the savings. All this puts the ROG Xbox Ally in an awkward position—well above the price range of most gaming handhelds, with exceptions like Lenovo's pricey Legion Go. (That console starts around $700.) Xbox die-hards won't see the next major Xbox console until 2027, so it's easy to imagine many of them snapping up a ROG Xbox Ally or Ally X in the meantime. But other gamers now have loads of options, many of which will be easier on their wallets. Can the ROG Xbox Ally really command that premium? The key to the ROG Xbox Ally's success may have as much to do with supporting other platforms as it does with having Windows 11/Xbox support onboard. Xbox President Sarah Bond recently suggested that the ROG Xbox Ally will support other platforms, despite having a handheld-friendly version of Xbox as its main platform. If you buy a ROG Xbox Ally, you will likely have access to your Steam library and your libraries on other platforms. And, perhaps, that's why Microsoft appears to be considering a higher price tag. The other handhelds presumably won't be able to run Xbox games. If Xbox can become the one platform that lets you run almost any title, players may be willing to set aside their consoles from Valve, Lenovo, and the like. For now, the best we can do is speculate. Microsoft hasn't confirmed the pricing from the retailer's website, and tariffs could change the landscape at any time.

Lifetime Access to the Full Microsoft Office Suite Is 81% Off, Practically Free Now Ahead of the New Semester
Lifetime Access to the Full Microsoft Office Suite Is 81% Off, Practically Free Now Ahead of the New Semester

Gizmodo

time4 hours ago

  • Gizmodo

Lifetime Access to the Full Microsoft Office Suite Is 81% Off, Practically Free Now Ahead of the New Semester

A lot of things which used to be one-time purchases want to try and convince you to subscribe instead. It can have some benefits to subscribe, but sometimes you just want to pay once and be done with it. If you're feeling like this when it comes to Microsoft Office programs, then you're in luck. StackSocial has an amazing deal that brings the price of a Microsoft Office Professional 2021 Lifetime License down from $220 to just $40. That's a huge 81% discount, but this deal won't last forever. So, if you want to get your hands on it, you'd better be quick. See at StackSocial Microsoft Office Professional 2021 comes with Word, Excel, PowerPoint, Outlook, OneNote, Publisher, Access, and the free version of Teams. These are pretty much all of the software options you need to work or study on whatever device you're using. Word is an excellent tool for anyone who likes writing, no matter how professional or unprofessional. Excel is essential for not just accounting, but also budgets, and somehow, game design. PowerPoint is an excellent choice for presentations, even though most of us have some mild degree of bar chart flashbacks when using it. Outlook is great for emails, and allows for all sorts of useful functions if you're sending a lot of them. OneNote is an amazing way to take notes and share ideas with people in an easy-to-understand way. Publisher is a great piece of software for those looking to design newsletters and brochures. Access is a great databasing software, and Teams is better than Skype, and also still works. Buying this will grant access to all of these for whatever device you activate the code on. You'll then be able to use them all from then on for the rest of time. Well, you'll be able to use them until your laptop or PC gives up on things. That's because this isn't tied to your account, but the device you activate it on. Make sure you keep that in mind before activating it on your phone or something by accident. While you could sign up for Microsoft 365 and pay for access to all of these programs monthly, it's better for a lot of us to save a huge chunk of change and pick them all up while it's just $40. Just keep in mind the deal will end soon, so if you do want this, you should buy it quickly. See at StackSocial

Mercedes-Benz brings Microsoft Teams calls to cars
Mercedes-Benz brings Microsoft Teams calls to cars

Yahoo

time5 hours ago

  • Yahoo

Mercedes-Benz brings Microsoft Teams calls to cars

Mercedes-Benz has expanded its partnership with Microsoft to bring popular business tools, including Teams, into its cars. The partnership introduces advanced Microsoft business productivity and collaboration tools, starting with the all-new CLA. The productivity enhancements will be rolled out this summer, starting with the powered fourth-generation MBUX in the new CLA. The updated Meetings for Teams app in Mercedes-Benz vehicles now allows drivers to participate in Teams calls using the in-car camera, ensuring compliance with local laws and focusing on safety. The app automatically disables the video stream when the camera is activated to prevent driver distraction. Additionally, the app features a new dashboard with upcoming meetings, quick access to frequent contacts, and an expanded chat function, all designed to enhance productivity while driving. Mercedes-Benz is the first to natively integrate Microsoft Intune into a vehicle operating system, creating a secure workspace on wheels. This integration into allows customers to manage business and private data separately and provides IT administrators with tools to control access rights and security policies. The integration supports productivity apps like MBUX Notes and Calendar and will be available in Europe and the US. The collaboration also aims to bring Microsoft 365 Copilot into Mercedes-Benz vehicles, marking one of the first in-car applications of generative AI. The advanced AI will assist users in summarising emails, retrieving client information, and managing tasks through voice commands, potentially making the vehicle a third workspace alongside the office and home office. Mercedes-Benz Group chairman of the board of management Ola Källenius said: 'Through our industry-leading collaboration with Microsoft, we are making it even easier for our customers to stay productive while on the move. By integrating the latest Microsoft workspace tools, such as Microsoft Teams, directly into our new operating system, we've created an intuitive and safe user experience that boosts efficiency and reduces distractions at the same time.' "Mercedes-Benz brings Microsoft Teams calls to cars" was originally created and published by Just Auto, a GlobalData owned brand. The information on this site has been included in good faith for general informational purposes only. It is not intended to amount to advice on which you should rely, and we give no representation, warranty or guarantee, whether express or implied as to its accuracy or completeness. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content on our site. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store