Threat alert: New malware attacks from Excel files
Got an Excel attachment in your email? Double-check it before downloading – it could be infected with malware.
In its 2021 Q4 Threat Insights Report, HP’s Wolf Security service detected a dramatic 588% surge in computer and network malware infections involving Excel add-in files that end in .XLL.
Double-clicking these attachments or links opens Excel, which then prompts the user to install and activate the add-in. These particular malware attacks don’t require the user to exit Excel’s Protected View and enable macros.
Prevent Excel malware sneak attacks
The HP Wolf Security report offered three different options for organizations to protect themselves from .XLL malware attacks:
- Have IT configure your firm’s email gateway to block inbound messages that have .XLL attachments. Some email gateways already do this because .XLL files are dynamic link libraries, a type of file not typically sent by email.
- Configure Excel to allow only add-ins from trusted publishers. From the File menu, click on Options, then select Trust Center and click on the Trust Center Settings box to the right. Trusted publishers, locations, documents and add-in catalogs are the top options in the Trust Center menu.
- Configure Excel to disable all proprietary add-ins. This can be done under “Add-Ins” in the Excel Trust Center Settings.
Free Training & Resources
White Papers
Provided by UJET
White Papers
Provided by Anaplan
White Papers
Provided by Anaplan
Further Reading
Insider trading is morally wrong and illegal. People go to jail for it. The risks to one’s reputation and freedom outweigh the money ...
That familiar voice on the phone? Could be a deepfake. The face you’ve seen a thousand times in meetings? Don’t assume it’...
Cybercriminals have zeroed in on finance, where every click can move real money. In fact, 79% of companies experienced an attempted or actu...
Cybercriminals who are out to steal your company’s money are getting smarter. Even a password that uses a capital letter, at least one nu...
Looks like company executives are damned if they do and damned if they don’t report a financial violation committed by their companie...
About 90% of U.S. companies were targeted by cyber‑fraud last year – almost a 25% increase from the previous year. The rise doesn...