5 ms·
'Fully undetectable' Windows PowerShell backdoor detected
- raydiatian 4y agoI find it kind of astonishing that Word documents have been an attack vector (a) in the first place and (b) for as long as they have without a sealing patch. Like, why do I need my word document to contain any sort of RPC invoking capability.
- zamadatix 4y agoMacro enabled documents enable you to programmatically publish content. E.g. you can pull from an Access database or an Excel sheet and have it autogenerate formatted quotes for customers. Such flexibility is naturally a security risk which is why it has been made so difficult for the typical user to run this kind of document without jumping through hoops to do so but it makes no sense to remove the functionality from Word itself in the same way it doesn't make sense to remove PowerShell.
- raydiatian 4y agoDid it ever make sense to put it there in the first place?
- zamadatix 4y agoI mean why not. Remember this isn't a standard Word document John Doe is going to type his homework assignment in it's a whole different filetype for a different use case. Office got VBA functionality before Netscape or IE were even a thing so it has a valid excuse of why the default security restrictions came later - the internet wasn't really a threat model yet.
- raydiatian 4y agoFair arguments, esp cart coming before horse security-wise
- sph 4y agoNot fully undetectable after it's been detected now, is it?
- technion 4y agoHonestly if if a big enough organisation hasn't disabled untrusted Word macros by policy several years ago their odds of being ransomware victims by now would be close to 100%, and based on what I've seen the odds of having been victims 10+ times are pretty high. One new malware in this space isn't game changing, and new fully undetectable variations show up every day.
- vmoore 4y agoWhat if PowerShell itself is the backdoor? You can remove PowerShell from Windows as a hardening/mitigation strategy. I do it on all my systems. I regularly see threat hunters disclosing how 99% of malware leverages the shit out of PowerShell to drop payloads.
- majkinetor 4y agoYou can't really remove powershell as it can get integrated trivially.
- 1MachineElf 4y agoeBPF has landed in a lot of monitoring/observability use cases. Microsoft has worked on porting eBPF to Windows. I speculate this "undetectable" backdoor problem may be solved with that combination.