We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
78,713 News Articles

Rigged Word docs used to attack Windows PCs

New Word attacks pose as news about Tibet

Security software developer Trend Micro has warned PC users of new email attacks which use rigged Microsoft Word documents.

Trend Micro said the phony emails claim to contain news about Tibet and its government in exile, but actually carry attachments that are malformed Word documents designed to exploit a vulnerability in parsing the popular word processing system's file format.

When opened, the malicious documents deposit a Trojan horse on the victim's Windows PC, said Trend Micro in a post to its security blog.

Trend Micro said the names on the fake Word documents include the following:

- CHINA';S [sic] OLYMPIC TORCH OUT OF TIBET 1.doc
- 2007-07 DRAFT Tibetan MP London schedule.doc
- DIRECTORY OF TIBET SUPPORT GROUPS IN INDIA.doc
- Disapppeared [sic] in Tibet.doc

Another security firm, Symantec, confirmed the new attacks but said that it has received only "a small number" of submissions from customers regarding the exploit.

"This social engineering technique has been seen before," said Trend Micro researcher Jake Soriano on the TrendLabs Malware blog. "In October, a Trojan rode on the newsworthiness of the monk-led protests in Myanmar ... arriving as an attachment to spam [that] purported to be a message of support from the Dalai Lama to the monks."

Symantec repeated the long-standing advice that users consider banning Office documents that originate from unknown senders and exercise caution in dealing with unsolicited emails, particularly those with attachments.

Microsoft has patched Word several times in the past two years - most recently in May 2007, when it holes in the way the application handles documents. The company has also been promoting its newest suites, Office 2007 for Windows and Office 2008 for Mac, as being more secure on the file format front than their predecessors, and it has locked down Office 2003 by limiting the number of formats users can open.

For more security news, reviews and tutorials, see Security Advisor


IDG UK Sites

Top 5 Android tips and tricks for smartphones and tablets

IDG UK Sites

How to join Apple's OS X Beta Seed Program: Get OS X Yosemite on your Mac before public release

IDG UK Sites

Why the BBC iPlayer outage was caused by a DDoS attack: Topsy and Tim isn't *that* popular

IDG UK Sites

BBC using Glasgow 2014 Commonwealth Games to trial 4K/UHD, pan-around video, augmented video and...