logo

New Attacks, Old Tricks: How OneNote Malware is Evolving

ID: fa4da82d-ba7c-5673-817e-074318c50387

STIX ID: report--fa4da82d-ba7c-5673-817e-074318c50387

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report analyzes a OneNote-based malware sample that embeds HTA, WSF and VBScript artifacts which, when executed by a user, run PowerShell downloaders to fetch and execute additional payloads. The author presents static analysis of the extracted scripts and URIs, demonstrates how malicious files are hidden behind a faux UI element in OneNote, and recommends mitigations including user awareness, a Sysmon detection rule, disabling Windows Script Host, and enforcing signed PowerShell execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.