{"id":198473,"date":"2022-08-11T11:17:56","date_gmt":"2022-08-11T09:17:56","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=198473"},"modified":"2025-07-01T20:32:00","modified_gmt":"2025-07-02T03:32:00","slug":"scammers-have-moved-on-from-macros","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/scammers-have-moved-on-from-macros\/","title":{"rendered":"Scammers have moved on from Macros to find a new way of infecting your machine"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Recently we\u2019ve covered several stories about <a href=\"https:\/\/microsoft-excel.en.softonic.com\/articles\/microsoft-excel-macro-malware\" target=\"_blank\" rel=\"noreferrer noopener\">scammers using Office macros<\/a> to infect user devices and <a href=\"https:\/\/microsoft-office-2007.en.softonic.com\/articles\/microsoft-announces-its-disabling-macros-to-protect-office-apps-from-malware-attacks\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft\u2019s subsequent campaign<\/a> to shut them down. Well, Microsoft\u2019s campaign has certainly enjoyed a level of success, but it seems that the move has forced the scammers to look elsewhere.<strong> Scammers are now using shortcut .ink files in their attempts to infect your device<\/strong>. Let\u2019s go through all you need to know.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft 365\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-logo-xl,f_auto\/p\/e7c83350-96d9-11e6-af79-00163ed833e7\/2296076294\/microsoft-365-icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft 365<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download Now<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Analysts at <a href=\"https:\/\/threatresearch.ext.hp.com\/hp-wolf-security-threat-insights-report-q2-2022\/\" target=\"_blank\" rel=\"noreferrer noopener\">HP Wolf Security<\/a> have discovered<strong> an 11% rise in certain files, including .ink files, being used to push malware over the last quarter<\/strong>. This data comes from an analysis of millions of different endpoint devices. The analysts also discovered a variety of different ways that the scammers have been using to try and get the corrupted files onto your devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>One of the main tricks used by these malicious actors is to compress the files<\/strong>, which makes then harder to detect. For example, if an infected file has been compressed into a .zip file and then sent as an email it is <strong>much harder for antivirus programs or your email provider\u2019s attachment scanner to discover it<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key element about shortcut files is that they are dynamic, meaning the scammers can alter the icon and the title in a way as to make it very difficult for users to identify them. For example,<strong> a scammer could give the file a PDF icon<\/strong> and then also include PDF in the file name, <strong>when in fact double-clicking it could run an executable file<\/strong> and load pretty much any type of malware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alex Holland who is the Senior Malware Analyst at HP Wolf Security had this to say about this new type of threat:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cAs macros downloaded from the web become blocked by default in Office, we\u2019re keeping a close eye on alternative execution methods being tested out by cybercriminals. Opening a shortcut or HTML file may seem harmless to an employee but can result in a major risk to the enterprise.\u201d<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This new type of threat requires enhanced levels of vigilance <\/strong>and HP Wolf Security recommends blocking any shortcut files sent as email attachments. If you or your team members are unsure about how to spot these types of scams you should check out our infographic, which will teach <a href=\"https:\/\/en.softonic.com\/articles\/how-to-detect-fakescam-emails-and-avoid-phishing-attacks-hi-res-version\" target=\"_blank\" rel=\"noreferrer noopener\">how to spot scam emails<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently we\u2019ve covered several stories about scammers using Office macros to infect user devices and Microsoft\u2019s subsequent campaign to shut them down. Well, Microsoft\u2019s campaign has certainly enjoyed a level of success, but it seems that the move has forced the scammers to look elsewhere. Scammers are now using shortcut .ink files in their attempts &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/scammers-have-moved-on-from-macros\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Scammers have moved on from Macros to find a new way of infecting your machine&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":198479,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[2717],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-198473","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionmicrosoft-365"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/198473","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=198473"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/198473\/revisions"}],"predecessor-version":[{"id":323387,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/198473\/revisions\/323387"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/198479"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=198473"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=198473"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=198473"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=198473"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=198473"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=198473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}