Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

Sometimes security breaches and hacking attacks come from the most unlikely of sources, even going so far as to utilize trusted applications to infect an endpoint or network. This is the case with a new phishing attack which uses the Calculator application that comes built-in with Windows in a very creative way. This is just one example of how hackers have been forced to innovate to combat the increasingly secure systems which businesses and users rely on today, and it should be a testament as to why you can never be too careful.

What is the Threat?

A security researcher who goes by ProxyLife on Twitter has reportedly discovered that there are several strains of malware and phishing attacks utilizing an outdated version of Microsoft’s Calculator application to find their way onto your network and launch their attacks—specifically the Windows 7 version of Calculator. The way that it works is that a cybercriminal tricks the user into downloading an ISO disc image which is disguised as a PDF or other similar file. This ISO contains a shortcut to an opened version of the Calculator application.

The Windows 7 Calculator can use what are called Dynamic Link Libraries in the same folder rather than defaulting to Windows’ system default libraries. The Calculator then runs the library, which is infected with malware. Later versions of Calculator do not have this capability, hence why an older version is necessary. Since Windows thinks that Calculator is a legitimate application, opening it in this way doesn’t set off any red flags within the system.

Should You be Worried?

At the end of the day, this is largely an obscure threat that sees hackers using the tools at their disposal in creative and different ways. It is not yet known if Microsoft has issued an update to Defender to put a stop to these types of attacks, but the long and short of it is that you probably won’t encounter this specific threat, as long as you are using proper security practices while browsing the Internet or checking your email.

Still, the idea that threats can use trusted and known applications in this way can make things a bit of a hassle for your IT team. These types of attacks might bypass the defenses built into your operating systems, but they can be caught if you are proactively monitoring your infrastructure for abnormalities. These abnormalities can then be contained, isolated, and eliminated. Of course, the problem here is that you likely wouldn’t find this type of threat if you weren’t actively looking for it—which is where we come in.

Proactively Monitor Your Network with Our Services

We know that it can be a challenge to keep your network safe. That’s why we make it easy with our remote monitoring services. Combined with comprehensive security solutions like a firewall, antivirus, spam blocker, and content filter, you’ll find that your network has never been safer. To learn more about what we can do for your business, contact us today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 22 February 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Internet Hardware Efficiency IT Support Malware Privacy Email Phishing Google Workplace Tips Computer Users Collaboration IT Services Hosted Solutions Mobile Device Quick Tips Ransomware Workplace Strategy Microsoft Small Business Cybersecurity Data Backup Communication Smartphone Passwords Saving Money Android Smartphones VoIP Business Management Mobile Devices communications Backup Managed Service Upgrade Data Recovery Managed IT Services Browser Social Media Microsoft Office Disaster Recovery Windows Tech Term Network Remote Internet of Things Automation Artificial Intelligence Facebook Cloud Computing Covid-19 Gadgets Remote Work Productivity Server Managed Service Provider Current Events Miscellaneous Holiday Outsourced IT Information Spam Employee/Employer Relationship Encryption AI Windows 10 Training Office Business Continuity Compliance Data Management Government Business Technology Bandwidth Windows 10 Blockchain Virtualization Wi-Fi Apps Two-factor Authentication Mobile Office Data Security Employer-Employee Relationship Chrome Managed Services Budget Voice over Internet Protocol Mobile Device Management Networking Apple Gmail App Vendor Applications Information Technology Access Control Office 365 Hacker Tip of the week Avoiding Downtime Conferencing Marketing How To BDR WiFi BYOD Computing Virtual Private Network Risk Management Health Help Desk Computers Analytics Office Tips Augmented Reality Retail Website Storage Healthcare Password Bring Your Own Device Managed IT Services Operating System HIPAA Big Data Router Display Printer Paperless Office Windows 11 Infrastructure 2FA Customer Service Monitoring Excel IT Support Document Management Remote Workers Telephone Scam Data loss Firewall Cooperation Free Resource Project Management Windows 7 Patch Management Going Green Save Money Microsoft 365 The Internet of Things Remote Monitoring Vulnerability End of Support Vendor Management Solutions Cybercrime Social Cryptocurrency User Tip Modem Processor Computer Repair Mobile Security Customer Relationship Management Holidays Virtual Desktop Data storage LiFi Data Storage Smart Technology Supply Chain Hacking Presentation Outlook Video Conferencing Machine Learning Managed Services Provider Saving Time Money Virtual Machines Professional Services Wireless Technology Humor Managed IT Service Maintenance Sports Downloads Antivirus Mouse iPhone Word Licensing Entertainment Administration Vulnerabilities Data Privacy Images 101 Telephone System Multi-Factor Authentication Robot Mobility Safety Cost Management Settings Printing Wireless Content Filtering IT Management VPN Employees Meetings YouTube Physical Security Integration Managing Costs Amazon IBM Username Point of Sale eCommerce Black Friday SSID 5G Google Docs Database Surveillance Unified Communications Virtual Assistant Outsource IT Experience Tech Support IT Technicians Virtual Machine Environment Running Cable Media Network Management Bitcoin Proxy Server Reviews Google Wallet Cookies Monitors Cyber Monday Medical IT Competition Tactics Development Hotspot Transportation Small Businesses Websites Mirgation Hypervisor Displays Laptop Windows 8 Shopping Drones Nanotechnology Optimization PowerPoint SharePoint Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing Chatbots Halloween Navigation User Management PCI DSS Lenovo Gig Economy Screen Reader Writing Distributed Denial of Service Workplace Service Level Agreement Internet Service Provider Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Private Cloud Identity Scary Stories Evernote Paperless IP Address Server Management Regulations Compliance Hacks Superfish Bookmark Identity Theft Smart Tech Memes Co-managed IT Fun Download Net Neutrality Deep Learning Twitter Alerts SQL Server Technology Care Error History Business Communications Recovery Financial Data Browsers Smartwatch Connectivity IT Education Social Engineering Break Fix Scams Hard Drives Domains Upload Procurement Remote Computing Azure Hybrid Work Mobile Computing Cyber security Multi-Factor Security Tech Human Resources Social Network Telework CES Tablet IoT Communitications Dark Web Cables Search Refrigeration Public Speaking Trends Supply Chain Management Best Practice Alert File Sharing Regulations Buisness Dark Data Google Calendar Term Google Apps Lithium-ion battery Managed IT Customer Resource management FinTech Entrepreneur Data Analysis Legal Star Wars IT Assessment IT solutions How To Microsoft Excel IT Maintenance Gamification Flexibility Business Growth Notifications Staff Value Business Intelligence Organization Travel Social Networking Legislation Shortcuts Undo Techology Fileless Malware Digital Security Cameras Google Maps Smart Devices Ransmoware Cortana Wearable Technology Memory Vendors Content Remote Working Alt Codes Health IT Unified Threat Management Motherboard Data Breach Downtime Comparison Google Play Be Proactive Unified Threat Management Directions Videos Assessment Electronic Health Records Hosted Solution Permissions Workforce Wasting Time Threats Typing Trend Micro Network Congestion Specifications Security Cameras Workplace Strategies Application User Error Microchip Google Drive Internet Exlporer Software as a Service Fraud Meta Knowledge

Blog Archive