Cryptojacking Scripts Could Soon Invade Your Word Documents

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Jan 8, 2017
1,321
8,958
2,279
Brazil
Cryptojacking scripts that mine Monero via JavaScript code can also run inside Word files, security researchers have discovered.

This is possible via a new feature added to recent versions of Microsoft Word that allows users to embed Internet videos inside Word files without having to inject the actual video file inside the document itself.

Word-cryptojacking-insert.png


Users can copy-paste a video's iframe embed code inside a Word popup, and the video will appear in the document the next time they open it.

If they press the "Play" button that appears over the video's iframe, the video loads and plays inside a popup.
..............................
..............................