Microsoft warns of "massive" phishing campaign using Excel macros

The emails claim to be coronavirus-related, but attachments attempt to hack into PCs and take control

Microsoft has warned of a "massive" phishing campaign that uses coronavirus-themed emails to deliver attachments containing malicious Excel 4.0 macros.

These malware-laced emails, which have the subject line  “WHO COVID-19 SITUATION REPORT," claim to come from the Johns Hopkins Center for Health Security, according to Microsoft. 

"The COVID-19 themed campaign started on May 12 and has so far used several hundreds of unique attachments,” the company's Security Intelligence team announced in a series of urgent tweets

If opened, the email’s attached Excel files will show a security warning and graph purporting to display coronavirus cases in the US. But if they’re allowed to run, the malicious Excel macros will download and run NetSupport Manager, a popular remote access tool that Microsoft’s security team says “is known for being abused by attackers to gain remote access to and run commands on compromised machines.”

The phishing attack then connects to a server that sends commands to the hacked PC.

“For several months now, we’ve been seeing a steady increase in the use of malicious Excel 4.0 macros in malware campaigns,” Microsoft warned. “In April, these Excel 4.0 campaigns jumped on the bandwagon and started using COVID-19 themed lures.” 

This is the second time in two months that Microsoft has sounded an alarm about cybercriminals taking advantage of the ongoing coronavirus crisis to trick users into downloading malware onto their devices. 

In April, Microsoft’s Security Intelligence team publicly warned of “prolific” hackers using Trickbot malware. Posing as the “USA Volunteer Organization” and the “USA Humanitarian Group,” hackers sent out hundreds of emails purporting to offer free coronavirus medical advice. Instead, those emails aimed to install malware via attachments.

To avoid raising red flags, phishers aren’t putting malicious URLs in emails, Microsoft recently warned on Twitter. “Instead, they leverage legitimate web services or use attachments that contain the link to the phishing site,” the company said.

There are multiple ways to launch a phishing attack, but email has become the platform of choice. It’s incredibly cheap to send messages to thousands of recipients, and at such a scale the scam only needs to fool a handful of victims to be lucrative.

You can avoid falling victim to these attempts by following our 10 quick tips for identifying phishing emails.

Featured Resources

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Simplify cluster security at scale

Centralised secrets management across hybrid, multi-cloud environments

Download now

The endpoint as a key element of your security infrastructure

Threats to endpoints in a world of remote working

Download now

2021 state of IT asset management report

The role of IT asset management for maximising technology investments

Download now

Recommended

What is hacktivism?
hacking

What is hacktivism?

13 Oct 2020
Microsoft: Iranian hackers are exploiting ZeroLogon flaw
Security

Microsoft: Iranian hackers are exploiting ZeroLogon flaw

6 Oct 2020
Yes, you can use Excel as an enterprise database tool
databases

Yes, you can use Excel as an enterprise database tool

5 Oct 2020
Need Excel training? Try these 10 cheap or free options
Microsoft Windows

Need Excel training? Try these 10 cheap or free options

17 Aug 2020

Most Popular

Microsoft CEO warns of video call fatigue
video conferencing

Microsoft CEO warns of video call fatigue

7 Oct 2020
Raspberry Pi Compute Module 4 launches with PCIe support
Hardware

Raspberry Pi Compute Module 4 launches with PCIe support

19 Oct 2020
Google blocked record-breaking 2.5Tbps DDoS attack in 2017
Security

Google blocked record-breaking 2.5Tbps DDoS attack in 2017

19 Oct 2020