← Back to Pulse Feed
PULSE DETAIL
Trustwave SpiderLabs “noted” in Part 1 and Part 2 of our OneNote research that OneNote has been used as a malware delivery mechanism now we will shift gears and focus on several OneNote decoy notes SpiderLabs has discovered that deliver malware families like Qakbot, XWorm, Icedid, and AsyncRAT. While the malware payload can change, the techniques have generally been the same. The recent uptrend of the OneNote spear phishing campaign that SpiderLabs has observed since December 2022 has led us to additional investigations on this threat.
MITRE ATT&CK & Malware Families
Indicators of Compromise (2 / 171 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 13697ddb77c6cdfb0fba6bc2eae680b44cefd47d | — | 2023-03-10 | |
| FileHash-SHA1 | dd16fd294e7776277435bac34c4bdac60263281d | — | 2023-03-10 |