ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Emotet now utilizing Onenote for its spam campaigns

Kyle by Kyle
March 26, 2023
in Malware
Reading Time: 3 mins read
Emotet onenote banking trojan
Share on FacebookShare on Twitter

The infamous Emotet malware has adopted a new tactic to spread its infection. Cybercriminals are now distributing the malware via email attachments in Microsoft OneNote format. The move is a calculated attempt to circumvent the security measures put in place by Microsoft and to target a broader range of victims.

Emotet is known for its advanced and sophisticated attack techniques. Historically, Emotet has been distributed via Microsoft Word and Excel attachments that contain malicious macros. If a user opens the attachment and enables macros, a DLL is downloaded and executed, which installs the Emotet malware on the device.

Once loaded, the malware steals email contacts and content for use in future spam campaigns. It also downloads other payloads, providing initial corporate network access. This access is used to conduct cyberattacks against the company, which could include ransomware attacks, data theft, cyber espionage, and extortion.

Emotet’s past activity has been sporadic, with the botnet taking breaks and starting again at irregular intervals. Towards the end of 2022, it went into inactivity for three months before resurfacing recently with a new spam campaign. However, this campaign was ineffective as Microsoft had begun automatically blocking macros in Word and Excel documents, including those attached to emails, making it difficult for Emotet to infect targets.

emotet word infection.
How Office macros have been used in the past to infect unsuspecting users

Emotet makes the switch to Microsoft OneNote

To bypass Microsoft security restrictions, Emotet has switched to a new attack method. Security researchers have spotted a recent Emotet spam campaign that uses malicious Microsoft OneNote attachments. These attachments are distributed in reply-chain emails that impersonate guides, how-tos, invoices, job references, and more.

Emotet phishing email
Emotet phishing email example

The Microsoft OneNote documents in the emails display a message stating that the document is protected and prompts the user to double-click the “View” button to display the document correctly.

microsoft onenote attachment
How the threat actors lure users into executing the payload

When the user clicks the “View” button, it launches an embedded design element that overlays the OneNote document. This design element includes a VBScript file called “click.wsf,” which is heavily obfuscated and downloads a DLL from a remote, likely compromised, website and executes it.

showing embedded file

click wsf image
Obfuscated VBScript contained in the click.wsf script

Although Microsoft OneNote displays a warning message when a user tries to launch an embedded file, history has shown that many users commonly click on “OK” to get rid of the alert.

onenote warning
The warning that appears when executing the click.wsf script

If the user clicks on the “OK” button, the click.wsf VBScript file will execute, downloading the Emotet malware as a DLL and storing it in OneNote’s Temp folder:

"%Temp%\OneNote\16.0\Exported\{E2124F1B-FFEA-4F6E-AD1C-F70780DF3667}\NT\0\click.wsf"

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

It then launches the random-named DLL (Virustotal) using regsvr32.exe, quietly running on the device, stealing emails, contacts, and waiting for further commands from the command and control server.

Blocking Malicious Microsoft OneNote Documents

Due to multiple malware campaigns using malicious Microsoft OneNote attachments, Microsoft will be adding improved protections in OneNote against phishing documents, but there is no specific timeline for when this will be available to everyone.

However, Windows admins can configure group policies to protect against malicious Microsoft OneNote files. Admins can use these group policies to either block embedded files in OneNote, disable the ability to launch file attachments in OneNote or configure the application to warn users when they attempt to launch embedded files.

attachments blocked
Attachments being blocked in Microsoft OneNote

The recent Emotet malware campaign using Microsoft OneNote documents demonstrates the increasing sophistication of cybercriminals and the need for constant vigilance to keep systems secure. Companies must educate their employees on the dangers of opening unknown attachments and enable macro blockers in Office applications. IT administrators should also consider implementing group policies to protect against malicious Microsoft OneNote attachments.

It is essential to stay updated with the latest threat intelligence and take all possible measures to protect systems against the newest malware campaigns. This includes installing the latest security updates, using anti-malware software, and conducting regular backups. By staying proactive and vigilant, companies can protect their sensitive data and avoid

Tags: botnetEmotetmalware
Previous Post

Pompompurin of BreachForums Arrested and Charged

Next Post

Amazon bans Flipper Zero

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.