Black Arrow Cyber Advisory 30 August 2023 – Think Opening PDFs is Safe?

This alert covers a recent change in attacker tools, tactics and procedures (TTPs) and is intended to raise awareness so that organisations can defend against these evolving attacks, where necessary through educating their staff and users on these latest changes.

Executive Summary

Research from the Japanese Computer Emergency Response Team (JPCERT) has found that hackers are utilising polygots, which are files that feature two formats and can be executed as more than one file type, to conduct attacks. Specifically, malicious word documents are being hidden within PDF documents to escape detection software.

What’s the risk to me or my business?

There is a risk if the disguised polygot is opened as a word document rather than a PDF document then it will enable a macro to run. The macro will then cause the victims device to download and install malware, impacting the confidentiality, integrity and availability of data. Worryingly, whether the polgygot opens as a PDF or Word document is dependant on the application opening it.

What can I do?

Microsoft’s default security setting is to disable macros from running on Microsoft Office files, and only files that were not downloaded from the internet can have macros enabled without going through multiple steps. Even with this control in place, organisations should remain vigilant and be aware that PDF files, like anything else, are susceptible to malicious modification.

Further information can be found below:

https://www.bleepingcomputer.com/news/security/maldoc-in-pdfs-hiding-malicious-word-docs-in-pdf-files/

Need help understanding your gaps, or just want some advice? Get in touch with us.

#threatadvisory #threatintelligence #cybersecurity

Previous
Previous

Black Arrow Cyber Threat Briefing 01 September 2023

Next
Next

Partnering with Hampshire Chamber of Commerce on Managing a Cyber Security Incident