• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

This Excel malware even forces you to fill out a dreaded CAPTCHA form

June 19, 2020
Share on FacebookShare on Twitter

Microsoft has identified a new Excel malware campaign that uses a novel technique to bypass traditional antivirus software and other security solutions.

According to the firm, cybercriminal syndicate Chimborazo is distributing a rigged Excel document capable of infecting victims with the password-stealing GraceWire trojan. Before the Excel file is downloaded, however, the victim is asked to fill out a CAPTCHA form, used in legitimate scenarios to establish whether a user is human or not. 

By concealing malware behind a CAPTCHA wall, which in essence requires the user to activate the download manually, hackers are more likely to successfully bypass security systems that scan for automated malware downloads.

Microsoft Excel malware

Microsoft Security Intelligence has reportedly been tracking the work of Chimborazo at least since January, and has dubbed the ongoing Excel malware campaign Dudear.

“CHIMBORAZO, the group behind Dudear campaigns that deploy the info-stealing Trojan GraceWire, evolved their methods once again in constant pursuit of detection evasion,” the team tweeted. “The group is now using websites with CAPTCHA to avoid automated analysis.”

The group has also been seen to distribute the infected Excel file via phishing campaigns and embedded web links. In a number of recent scenarios, phishing emails link out to redirector sites or contain malicious HTML attachments. In all instances, Chimboranza leaned on the CAPTCHA technique to minimize the risk of detection.

While using CAPTCHA to evade security software is not unheard of, neither is it common – and the technique is fast becoming this particular hacking group’s modus operandi.

Chimboranza is expected to continue to adapt its method of malware delivery in the coming months in a bid to maximize infection rates and head off measures put in place by security teams. For this reason, users are advised to exercise caution when downloading unsolicited Excel files – or files of any other type – and to examine CAPTCHA widgets for signs of illegitimacy.

Via Ars Technica

Next Post

How Reliance Jio Platforms became India’s biggest telecom network – TechCrunch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Today’s Hurdle hints and answers for March 17, 2026
  • GamerForge Review: Resident Evil Requiem – A Bloody Welcome Home
  • Amazon just announced another Prime Day, and it starts next week — FAQ, early deals, and everything you need to know about the Big Spring Sale
  • Best Fire Stick deal: Save $25 on Amazon Fire Stick 4K Select
  • Best power station deal: Save $700.01 on EcoFlow Delta 2 Max with solar generator

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously