Microsoft blocks internet-downloaded XLL add-ins to prevent malware spread

Share post:

Microsoft says it will implement a new security measure to discourage hackers from using XLL add-ins to distribute malware.

Adversaries abusing Microsoft add-ins is a hobby due to its pervasiveness in corporate environments and personal computers, allowing threat actors to get a lot of mileage out of their malware.

The plan to implement the new measures resulted in the goal of combating the increasing number of malware attacks that have become more prevalent in recent months. According to Microsoft’s 365 roadmap, it will soon be available to worldwide desktop users of its Excel product in the Monthly Enterprise Channel, Semi-Annual Enterprise Channel, General Availability, Preview, and Current Channel.

“In order to combat the increasing number of malware attacks in recent months, we are implementing measures that will block XLL add-ins coming from the internet,” Microsoft says.

According to Microsoft, the new feature will be available in multi-tenant mode for desktop users in the Current, Monthly Enterprise, and Semi-Annual Enterprise channels in March.

After the changes are implemented, Microsoft 365 users will have improved protection that will prevent XLL add-ins from being downloaded from the internet. This means protection from bad actors who use the web to distribute malware. While the general availability of the upcoming capability is still subject to change, its arrival will be a significant improvement in Microsoft customers’ security.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

North Korean Job Scam Targeting IT Job Seekers

North Korea’s Lazarus advanced persistent threat (APT) group has launched a sophisticated campaign, “Operation 99,” targeting freelance software...

Hackers Exploit FastHTTP in High-Speed Microsoft 365 Attacks

Threat actors are employing the FastHTTP Go library to launch high-speed brute-force password attacks on Microsoft 365 accounts...

YouTubers Targeted As Cyberattackers Hide Infostealers in YouTube Comments, Google Search Results

Attackers have found a new way to infect people seeking pirated or cracked software: planting malicious download links...

New macOS Malware Exploits Apple’s Security Features to Stay Hidden and Steal User Data

A newly discovered variant of the Banshee macOS Stealer malware is putting 100 million Apple users at risk...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways