back to article Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an alert published on Sunday, CERT-UA says the activity is being driven by …

  1. Anonymous Coward
    Anonymous Coward

    Carry-on regardless

    To the russian attackers, please continue and don't stop until they discontinue this pile of crap

    1. Eric 9001

      Re: Carry-on regardless

      Why would microsoft ever discontinue such a cash cow?

      Microsoft wouldn't discontinue it even if every last instance was persistently exploited (oh wait, that's the whole idea of proprietary software - the developer exploits every last user).

      Interestingly the exploit doesn't seem applicable if you just used libreoffice, moreso if run on GNU/Linux.

      1. Fred Daggy Silver badge

        Re: Carry-on regardless

        To mangle Galbraith : "Under capitalism, vendor exploits user. Under communism, its just the same, hacker exploits user."

    2. werdsmith Silver badge

      Re: Carry-on regardless

      If Office and MS were to disappear from the desktop, whatever replaces it will become the focus of attacks and exploits. Be thankful that it is there

      As a diversionary shield to protect your Sanctimonious-ware.

      1. MacroRodent

        Re: Carry-on regardless

        The proper answer is diversity. This is why in biology, no virus manages to destroy all individuals of a species. To promote this, governements at least should use only open standard document formats, and these must be enforced: Like if a word processor (from whatever vendor or open-source project) messes the layout in an extensive test suite, it shall not be used. There are standards for items like paper sizes and even the properties of ball-point pen ink, so why not word processors?

    3. stungebag

      Re: Carry-on regardless

      Yes, I'm sure LibreOffice is sufficiently bulletproof to resist hacking attempts by a very powerful rogue state.

      1. david 12 Silver badge

        Re: Carry-on regardless

        LO has ~very little~ protection against typical .doc malware, such as document-event driven macros.

        1. Eric 9001

          Re: Carry-on regardless

          LO doesn't run macro's by default - it asks to run, which happens to be quite good at preventing macro attacks (it's clear that a document almost always should not use a macro).

  2. Anonymous Coward
    Anonymous Coward

    So...

    Are Windows 10 systems able to patch themselves? They represent what, half the systems out there? Seems Microsoft should patch them too, since it's Office not Windows that contains the flaw.

    1. Eric 9001

      Re: So...

      Yes, there is a remote backdoor in windows 10 that allows microsoft to make whatever arbitrary changes remotely (the auto-update feature).

      Although the exploit is carried out against office, a flaw in windows allows for attacker persistence - it's up to microsoft to choose whether to fix that flaw in windows 10 and choose if to roll out the patch to only "extended-support" systems or all systems.

    2. Roland6 Silver badge

      Re: So...

      Currently running Office 2019 on W10 (both x64 versions) on a couple of laptops.

      Whilst I had update other Microsoft products in Windows Update and within Office it was set to automatically update, I had to manually (in Office) click on the update now to get it to go and fetch and install the security update “now”; I suspect if I had waited a month the automatic update scheduler would have got around to applying the update.

  3. david 12 Silver badge

    Mitigation

    The mitigation offered blocked the specific malware -- it blocked use of the legacy IE engine used by the script.

    It ~appears~ to me that the bug is that you can avoid a authorization step by moving between 64bit Application and 32bit com object, but I may have misunderstood that.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon