Recently we’ve covered several stories about scammers using Office macros to infect user devices and Microsoft’s subsequent campaign to shut them down. Well, Microsoft’s campaign has certainly enjoyed a level of success, but it seems that the move has forced the scammers to look elsewhere. Scammers are now using shortcut .ink files in their attempts to infect your device. Let’s go through all you need to know.
Analysts at HP Wolf Security have discovered an 11% rise in certain files, including .ink files, being used to push malware over the last quarter. This data comes from an analysis of millions of different endpoint devices. The analysts also discovered a variety of different ways that the scammers have been using to try and get the corrupted files onto your devices.
One of the main tricks used by these malicious actors is to compress the files, which makes then harder to detect. For example, if an infected file has been compressed into a .zip file and then sent as an email it is much harder for antivirus programs or your email provider’s attachment scanner to discover it.
The key element about shortcut files is that they are dynamic, meaning the scammers can alter the icon and the title in a way as to make it very difficult for users to identify them. For example, a scammer could give the file a PDF icon and then also include PDF in the file name, when in fact double-clicking it could run an executable file and load pretty much any type of malware.
Alex Holland who is the Senior Malware Analyst at HP Wolf Security had this to say about this new type of threat:
“As macros downloaded from the web become blocked by default in Office, we’re keeping a close eye on alternative execution methods being tested out by cybercriminals. Opening a shortcut or HTML file may seem harmless to an employee but can result in a major risk to the enterprise.”
This new type of threat requires enhanced levels of vigilance and HP Wolf Security recommends blocking any shortcut files sent as email attachments. If you or your team members are unsure about how to spot these types of scams you should check out our infographic, which will teach how to spot scam emails.