logo

The Rising Trend of OneNote Documents for Malware delivery

ID: 8a331a78-fb12-5a19-b001-591d55cf04b0

STIX ID: report--8a331a78-fb12-5a19-b001-591d55cf04b0

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2023-03-30

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This report analyzes malicious OneNote documents used in phishing campaigns to distribute Qakbot and other malware families. It details OneNote file structure (FileDataStoreObject), an automated extraction method for embedded artifacts, two Qakbot campaign infection chains (HTA- and batch-based droppers that download DLL payloads executed via rundll32/mshta/powershell), runtime behavior, and provides associated IOCs and a malicious domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.