Forum Discussion

Norman Di Pasquale's avatar
Norman Di Pasquale
Iron Contributor
Oct 04, 2016

OneDrive for Business Phishing Virus -- Look Out!

A client of mine received the below email:

He unfortunately clicked on it, the URL had Onedrive in it, but was just redirecting to another HTTP page. The virus then sent the above email to all contacts in Outlook. Be vigilant, people.

    • Steven Collier's avatar
      Steven Collier
      MVP

      Umm, so what did it actually download an  the user allow to run ? I guess it wasn't a .docx, it must either be something with macros (.docm) or some kind of executable, either way the user must have allowed them to run for it to be able to hijack outlook to propogate.

       

      The social attack is one that many of my users would clearly fall for, but having clicked it I would hope that windows makes it pretty clear this isn't the file they were expecting.

      • Alexander Forst-Rakoczy's avatar
        Alexander Forst-Rakoczy
        Brass Contributor

        Curiosity killed the cat and lets phishers install viruses.

         

        Social engineering is the most dangerous attack. You can only try to educate your users.

Resources