Threat alert: New malware attacks from Excel files
Got an Excel attachment in your email? Double-check it before downloading – it could be infected with malware.
In its 2021 Q4 Threat Insights Report, HP’s Wolf Security service detected a dramatic 588% surge in computer and network malware infections involving Excel add-in files that end in .XLL.
Double-clicking these attachments or links opens Excel, which then prompts the user to install and activate the add-in. These particular malware attacks don’t require the user to exit Excel’s Protected View and enable macros.
Prevent Excel malware sneak attacks
The HP Wolf Security report offered three different options for organizations to protect themselves from .XLL malware attacks:
- Have IT configure your firm’s email gateway to block inbound messages that have .XLL attachments. Some email gateways already do this because .XLL files are dynamic link libraries, a type of file not typically sent by email.
- Configure Excel to allow only add-ins from trusted publishers. From the File menu, click on Options, then select Trust Center and click on the Trust Center Settings box to the right. Trusted publishers, locations, documents and add-in catalogs are the top options in the Trust Center menu.
- Configure Excel to disable all proprietary add-ins. This can be done under “Add-Ins” in the Excel Trust Center Settings.
Free Training & Resources
White Papers
Provided by Personify Health
Further Reading
Any business owner who paid employee salaries or health benefits during COVID-19 restrictions will be waiting a while longer for a tax cred...
Fraud has become an increasing concern for AP teams, and the financial impact is quite significant. Criminals are taking advantage of vario...
About 90% of U.S. companies were targeted by cyber‑fraud last year – almost a 25% increase from the previous year. The rise doesn...
The IRS is sounding the alarm about the top 12 – aka the “dirty dozen” – tax scams that are tripping up businesses,...
Twenty-six financial firms are on the hook for $392.75 million in fines for securities recordkeeping violations. Several of the brokers, de...
Hackers love attacking via email because of how easy it is to do. That’s why an ounce of email cyber security can prevent a ton of fr...