fermer
fermer
Le réseau de demain
Le réseau de demain
Planifiez votre chemin vers un réseau plus rapide, plus sûr et plus résilient, conçu pour les applications et les utilisateurs que vous prenez en charge.
          Essayez Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            Un leader sur SSE. Désormais leader en matière de SASE à fournisseur unique.
            Un leader sur SSE. Désormais leader en matière de SASE à fournisseur unique.
            Netskope fait ses débuts en tant que leader dans le Magic Quadrant™ de Gartner® pour le SASE à fournisseur unique.
              Sécuriser l’IA générative pour les nuls
              Sécuriser l’IA générative pour les nuls
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                La prévention moderne des pertes de données (DLP) pour les Nuls
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Réseau SD-WAN moderne avec SASE pour les nuls
                  Modern SD-WAN for SASE Dummies
                  Cessez de rattraper votre retard en matière d'architecture de réseau
                    Identification des risques
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        Les 6 cas d'utilisation les plus convaincants pour le remplacement complet des anciens VPN
                        Les 6 cas d'utilisation les plus convaincants pour le remplacement complet des anciens VPN
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          Colgate-Palmolive protège sa "propriété intellectuelle" "grâce à une protection des données intelligente et adaptable
                          Colgate-Palmolive protège sa "propriété intellectuelle" "grâce à une protection des données intelligente et adaptable
                            Netskope GovCloud
                            Netskope obtient l'autorisation FedRAMP High Authorization
                            Choisissez Netskope GovCloud pour accélérer la transformation de votre agence.
                              Let's Do Great Things Together
                              La stratégie de commercialisation de Netskope privilégie ses partenaires, ce qui leur permet de maximiser leur croissance et leur rentabilité, tout en transformant la sécurité des entreprises.
                                Solutions Netskope
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Support technique de Netskope
                                  Support technique de Netskope
                                  Nos ingénieurs d'assistance qualifiés sont répartis dans le monde entier et possèdent des expériences diverses dans les domaines de la sécurité du cloud, des réseaux, de la virtualisation, de la diffusion de contenu et du développement de logiciels, afin de garantir une assistance technique rapide et de qualité
                                    Vidéo Netskope
                                    Formation Netskope
                                    Grâce à Netskope, devenez un expert de la sécurité du cloud. Nous sommes là pour vous aider à achever votre transformation digitale en toute sécurité, pour que vous puissiez profiter pleinement de vos applications cloud, Web et privées.

                                      Cloud and Threat Report: Was 2020 the Year of the Malicious Office Document?

                                      Mar 16 2021

                                      Summary

                                      In the summer of 2020, there was a big, short-lived spike in malicious Office documents. The Emotet crew had been quiet in the spring and began leveraging their botnet to send extremely convincing phishing emails to their victims, often with a link to download an invoice or other document from a popular cloud service. Those documents contained malicious code that installed backdoors, ransomware, bankers, and other malware on unsuspecting victims’ computers. This blog post looks back at malicious Office document trends in 2020, with a preview of what is to come in 2021.

                                      This blog post accompanies the release of the February 2021 Cloud and Threat Report, which analyzes 2020’s most interesting trends in enterprise cloud and web security. In addition to highlighting the increase in cloud app usage, the Cloud Threat Report also highlights four other noteworthy trends from 2020:

                                      • Cloud app use continues to rise, with a 20% increase led by collaboration and consumer apps 
                                      • Cloud-delivered malware continues to increase, now representing 61% of all malware.
                                      • Cloud phishing continues to increase, with 13% of phishing campaigns hosted in the cloud and 33% targeting cloud app credentials.
                                      • Personal app usage in the enterprise continues to increase, with 83% of users accessing personal apps from managed devices.

                                      The calm

                                      The February 2021 Cloud and Threat Report examines trends in malicious Office documents at a quarterly granularity. In this blog post, we take a more granular look at a broader dataset. The chart below shows the percentage of malware downloads detected by the Netskope Security Cloud Platform that were Office documents. For the first three months of the year, Office documents represented nearly 20% of all malware downloads. This changed in April and May, in the early days of the COVID-19 pandemic, when the Emotet crew and other threat actors were relatively quiet. During that time, only 10% of malware downloads were Office documents. 

                                      Chart showing what percentage of all Office Documents were malware downloads.

                                      Throughout the year, the Office document format most favored by cybercriminals was the Excel spreadsheet, representing 61.1% of all the malicious office documents in 2020. Excel is most popular because it provides rich scripting capabilities that threat actors abuse for malicious purposes. Word documents were the second most popular, followed by a small selection of Powerpoint documents.

                                      Pie chart showing percentage of Office documents used for malware delivery

                                      The storm

                                      Everything changed over the summer. The Emotet crew began leveraging their extensive botnet to send phishing emails to their victims, often with a link to download an invoice or similar document from a popular cloud service. The documents contained malicious code that installed backdoors, ransomware, bankers, and other malware on unsuspecting victims’ computers. The malicious code typically took the form of an XSL script or VBA script that would construct and execute a second script. That second script would download the next stage payload. This was an evasion technique designed to bypass detection by traditional signature-based malware detectors at the time.

                                      At its peak in July, malicious Office documents represented 44% of all malware downloads.  Following the summertime spike, Office docs returned to the same levels as the beginning of the year before increasing into December. The December spike was driven primarily by Dridex, the second most popular crimeware family, which also favors Office documents as a delivery mechanism. 

                                      The aftermath

                                      In January 2021, a multinational effort that included Europol, the FBI, and the UK National Crime Agency, as well as agencies from Canada, France, Germany, Lithuania, the Netherlands, and Ukraine, teamed up to take down the Emotet botnet. January saw a dropoff from the December spike, but through February, malicious Office documents still represent nearly 20% of all malware downloads. What is going on? While the Emotet botnet has been taken down, the techniques used to craft evasive malicious Office documents remain available to other groups, like Dridex, that continue to use them for malware delivery. 

                                      Conclusions

                                      There were a couple of spikes in malicious Office documents in 2020, a summertime spike driven by Emotet and an end-of-year spike from Dridex. Despite the Emotet takedown, malicious Office documents are still a popular tool used by cybercriminals to deliver malware to their victims. Malicious Office documents currently account for 20% of all malware downloads, which we expect to continue through 2021.

                                      author image
                                      Ray Canzanese
                                      Ray is the Director of Netskope Threat Labs, which specializes in cloud-focused threat research. His background is in software anti-tamper, malware detection and classification, cloud security, sequential detection, and machine learning.
                                      Ray is the Director of Netskope Threat Labs, which specializes in cloud-focused threat research. His background is in software anti-tamper, malware detection and classification, cloud security, sequential detection, and machine learning.

                                      Restez informé !

                                      Abonnez-vous pour recevoir les dernières nouvelles du blog de Netskope