
Read more detailed guidance on blocking Microsoft OneNote at BleepingComputer. TrustWave described one such attack in January 2023 on the companys blog. To help organizations proactively defend against this activity, BleepingComputer posted comprehensive guidance on how to block malicious Microsoft OneNote files. Use of Microsoft OneNote in phishing attacks has increased in recent years. Specifically, threat actors behind the QakBot campaigns successfully used this tactic to compromise an organization and infect its network with BlackBasta ransomware.

Threat actors, including ransomware gangs, are actively using this delivery method to infect organizations. TYPE, WRITE, AND DRAW Write anywhere on the page and unleash your imagination Use your device's pen or your finger to write and draw with multiple. Microsoft OneNote is a tool for note-taking, free-form information gathering, and multi-user collaboration by Microsoft. Jot down your ideas, keep track of classroom and meeting notes, clip from the web, or make a to-do list, as well as draw and sketch your ideas. Last week, WaterISAC shared a DHS report on attackers successfully utilizing weaponized Microsoft OneNote files for malware distribution. OneNote is your digital notebook for capturing and organizing everything across your devices. Now, Microsoft has announced that it has improved the security system to ensure no malware can be side-loaded into documents via the OneNote app. Since mid-December 2022, threat actors have been increasingly exploiting Microsoft OneNote files to deliver malware and compromise victims.
