- Microsoft Word's Online Video feature allows hackers to hide cryptocurrency mining scripts in Word documents to secretly steal Monero from victims.
- Most cryptocurrency mining is done via an internet browser and is JavaScript based.
Microsoft Word documents can now be used by hackers to deliver a cryptojacking script—hijacking a victim's computer to mine the cryptocurrency Monero. According to
security researchers at Votiro, the attack utilizes Word's Online Video feature to commandeer the CPU.
The feature allows a Word user to simply paste the iframe embed code to add an internet video to a Word document. The video will then pop up in the Word document, and can be played the next time a user opens the document.
However, an attacker can add the cryptojacking script in with the video code, tricking the victim into performing Monero mining for them, the Votiro report said.