PowerShell used by malware to infect computers

According to the TrendLabs (TrendMicro) blog, the new type of malware, known as CRIGENT and nicknamed “Power Worm,” is delivered via infected Office files (Word docs or Excel spreadsheets). It contacts a malicious server and downloads a PowerShell script that sends info about the system back to the attacker and makes changes to registry entries to lower the Office security settings so it can infect all the Word and Excel files on the computer. Find out more about it here:

http://blog.trendmicro.com/trendlabs-security-intelligence/word-and-excel-files-infected-using-windows-powershell/

Leave a Comment

Your email address will not be published.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Scroll to Top