Cryptojacking to target MS-Word via Its Newly Added Features——–The new MS-Word update has launched the facility of adding Video, by using the iFrame code, into the documents. It can be played from the headless Web browser in the pop-up window, the most amazing thing being that  the file size of the video doesn’t get increased. This feature makes it possible for Crypto-jacking JavaScript to attack.Cryptojacking to target MS-Word


The Cybercrooks can host a beautiful video on the servers and then they may add Cryptojacking Script to Monero or to other Cryptocurrency. But when the user clicks on the video’s playback button, the browser gets launched. CoinHive or another such popular miner gets started earning crypto to the far away scammer.


This sort of problems can be prevented if MS-Word started to whitelist such domains and allows only YouTube or Vimeo Videos to get played. Some Security- Researchers are against of such solution. The hidden web browser mining has, on the other handexplained that this can be possible if the user doesn’t close the video, for a long time.


For their smooth transformation from one video to another, the hacker may upload longer video or short videos. Nowadays, the people desire to watch and download videos on YouTube more than in any other Channel.  But the question is who are going to watch or download movies in MS-Word?


The Hackers have to coax a thousand of users on the regular basis to open up Word booby-trapped documents, to make a profit out of that. They have understood the point that the people mostly, open the video-streaming services and stay there for a long time. So they are now trying to hack the services and place crypto miners over there because people while watching any movies usually don’t recognize high CPU and Processor loading. The hackers earn high profit through the websites like a torrent, game portals and other resources with pirated content.


The other products of MS-Office are secure because it provides access to certain domains. The online video facility is available in MS-Office other products like OneNote and PowerPoint.


Word macros are very famous among the malware users. The MS-Office Word was used by the hackers to develop spiteful scripts. Recently, Researchers have sensed the OLE function of MS products and have asked to be careful while working with MS-Word which has attached videos. One should always download the fresh updates which include the Internet Explorer window.  When Microsoft were informed about the security issues they neglected it. Thus, the user must be very careful while watching any videos on MS-Word, should use VPN to their traffic and not type anything on their personal data, especially from an unknown server.——————

