Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

KDE Announces “Bulletproof” KDE Suite with Three Years of Support

Since the KDE Project dropped LTS support for the KDE Plasma desktop environment despite some demand from people, they teamed up with Linux hardware vendor Kubuntu Focus and Techpaladin Software to provide three years of bug and security fixes for the KDE Plasma 6.6 desktop environment series through Kubuntu 26.04 LTS.

Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs

Coming a month after Wireshark 4.6.7, the Wireshark 4.6.8 release updates support for the ANSI_TCAP, ASN.1 BER, ASTERIX, BT ATT, BT AVRCP, BT BR/EDR RF, BT HFP, C12.22, CIGI, CMS, COSEM, EBHSCR, ESS, FP, GSM SIM, GTPv2, H.245, Kerberos, KNX/IP, LBMSRS, NAS-5GS, RELOAD, Rlogin, RRC, SSH, X.509AF, and X.509IF protocols.

Shelly 3.0.4 GUI Package Manager for Arch Linux Adds New Search Experience

Shelly 3.0.4 is here to introduce a new search experience, add an initial TUI (text-mode UI) to accompany the GUI and CLI interfaces, improve the AppImage integration, improve Flatpak support with end-of-life detection and rebase support, as well as a new remove dialog, and add an AUR link to the AUR detail view.

QEMU 11.1 Released with Universal Flash Storage (UFS) Emulation Support

Coming three and a half months after QEMU 11, the QEMU 11.1 release introduces Universal Flash Storage (UFS) emulation support for Write Booster (device-level caching) and Host-Initiated Defragmentation (HID) support based on the UFS 4.1 specification.

GNOME Devs Share GNOME Shell Design Ideas for Future GNOME Releases

As a GNOME user, I have to admit that some of these concepts are very exciting, especially the transparent panel. Not that I like using two panels/launchers (top and bottom), but this is the main reason most people think GNOME is “ugly” and are using an extension like Dash to Panel or Dash to Dock.

Internet Society

Advancing the Safer Internet Initiative for Everyone

When we launched the Safer Internet Initiative earlier this year, our message was clear: connectivity is essential, but it is not enough. Everyone needs to feel safe, protected, and empowered when they go online.

Youth in Action: Contributing to a More Connected and Inclusive Digital Future

Across the world, young people are shaping the future of the Internet in ways that reflect the realities of their communities.

LinuxGizmos.com

ESP32-C6 Home Automation Kit with ESPHome and Modular Sensors

Apollo Automation has launched the ESPHome Starter Kit, a modular smart-home development platform built around an ESP32-C6 board and designed to let users create ESPHome devices without soldering, breadboards, or writing code. The kit operates locally and can be used independently or integrated with Home Assistant.

2.16-inch AMOLED SF32LB52X-based dev board offers LoRa, GNSS, and Bluetooth 5.3

LILYGO’s T-Display SF32 is a compact development platform built around the SiFli SF32LB52X ultra-low-power AIoT microcontroller. The device combines a 2.16-inch 480 × 480 AMOLED touchscreen with dual Arm Cortex-M33 cores, an ePicasso 2.5D graphics engine, LoRa connectivity, Bluetooth 5.3, and onboard battery power.

1.35-liter mini PC runs Core Ultra 200 with triple displays and 96GB DDR5

Shuttle’s XPC slim DH810S is a 1.35-liter barebone PC supporting Intel Core Ultra 200 “Arrow Lake-S” processors with up to 24 cores and a 13 TOPS NPU. The system is intended for digital signage, POS/POI, healthcare, industrial, and edge AI applications.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Microsoft's Latest Move Will Accelerate the Adoption of GNU/Linux at the OEMs/Channel [original]
The latest move from Microsoft defies logic
Microsoft apparently just upped its Windows licence fee for OEM handheld and PC makers, and I'm taking it as an excuse to switch to Linux
Pretty bold to assume we all want to use Windows, Microsoft.
FSF Copycat "Software Freedom Conservancy" Makes Copycat FSF Award ("Award in Software Freedom"), Gives it to IBM Staff That Tried to Cancel FSF Founder
as expected
Games: Knytt Classic, GNOME Crosswords, 'Xodus', and More
Many gaming picks today
QEMU 11.1 Released with Universal Flash Storage (UFS) Emulation Support
QEMU 11.1 open-source virtualization software is now available for download with Universal Flash Storage (UFS) emulation support, ARM and RISC-V improvements, and more.
Rounding Up GNU/Linux Share to Double-Digit Market Share [original]
As of this morning
 
Today in Techrights
Some of the latest articles
KDE Announces “Bulletproof” KDE Suite with Three Years of Support
KDE announces “bullet-proof” KDE suite with three years of bug fixes and security updates for KDE Plasma 6.6 LTS and related KDE software.
Security Leftovers
Security picks
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Free, Libre, and Open Source Software Leftovers
FOSS leftovers
PostgreSQL and More
Databases related picks
Programming Leftovers
Development related picks
Linux Hardware, Open Hardware, and Android Leftovers
Arduino and more
Fedora and Red Hat Leftovers
especially the latter
today's howtos
Instructionals/Technical picks
Games: GodotFest, Gambonanza, and More
gaming leftovers
My kid's first PC won't run Windows—it'll use one of these 5 Linux distros instead
Most distro recommendations for kids focus on simplicity
Daniel Pocock in a British Election Today [original]
That helps raise awareness of issues he routinely covers
UserLAnd gives you a real Linux distro on Android—without Termux's compromises
Most Android users don't realize their phone can run a full Linux environment
New Forlinx SBC: A Raspberry Pi alternative with dual-core A53 and Linux support
Forlinx is introducing a new alternative to the Raspberry Pi
LightDM returns from the dark with first release in 4 years
LightDM, Ubuntu’s former display manager, has had its first new release in four years – and the first under a new set of maintainers
QEMU 11.1.0 Released with Recent ARM CPU Support & QMP Monitor Hot-Plug
QEMU, the open-source virtualizer and virtual machine monitor, released new 11.1.0 version one day ago
Free and Open Source Software
This is free and open source software
Sparky Linux just restored 32-bit support - why that still matters
Don't throw it away - Sparky Linux has decided not to give up on the aging architecture
VLC is Wrongly Blamed for Microsoft Defender's Clumsiness
VLC takes a long time to play MP3 on Windows? Blame it on Abusive Monopolist Microsoft Defender, not VLC
Super Hot Today [original]
Why travel to the Mediterranean?
Graphics/Games: LACT, 10 Million Pixels, Bottles, and More
latest 10 from GamingOnLinux
IBM's own conflict-of-interest and promotion of slop plagiarism (pyramid scheme)
Red Hat leftovers
Today in Techrights
Some of the latest articles
LWN Articles on Kernel and 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit
outside paywall today
Wireshark 4.6.8 Improves Protocol and Capture File Support, Fixes More Bugs
Wireshark 4.6.8 open-source network protocol analyzer is now available for download with updated protocol and capture file support, as well as various bug and security fixes.
Fairphone with Ubuntu Touch: Is It Feasible? 2026 Guide
Fairphone with Ubuntu Touch: Is It Feasible? 2026 Guide
today's leftovers
mostly GNU/Linux stories
Canonical Promotes Slop to Participate in the Pyramid Scheme, Ubuntu 26.10 Wallpaper Competition
Canonical and Ubuntu news
CachyOS Has New Release
CachyOS ISO out
KDE: KEcoLab, Skrooge, and Mankala
KDE updates
GNU/Linux Distributions and Operating Systems
3 picks
Free, Libre, and Open Source Software; Standards Discussed
FOSS mostly
Security Leftovers
Security patches and more
Exploring OpenBSD and "6 BSDs worth trying instead of Linux"
BSD picks
Update on openSUSE.Asia Summit 2026 Gettinf Agama dressed for success
openSUSE leftovers
IBM Red Hat Leftovers
Windows and more
Programming Leftovers
Development picks
today's howtos
only 4 today
Microsoft Has 62 Critical Holes
Windows TCO
Linux Devices and Open Hardware/Modding Leftovers
many for today
Games: Armada, Steam, Teufelskreis, and More
mostly from GoL
Proton GE Updated
3 picks regarding Proton GE
Mozilla Pushing Slop and Paying the Price for Outsourcing to Microsoft (Proprietary GitHub)
bad and bad
Linux 7.2-rc7
I can't say that I'm exactly thrilled about the size of this all
Android Leftovers
Android Just Lost A Major Player: Why OnePlus Leaving The USA Matters
6 essential Linux desktop features that still haven’t made it to Windows
It’s endured so much that many people are unaware of Linux’s desktop benefits
Free and Open Source Software
Termora offers an unusually comprehensive set of tools in a single open source application
Shelly 3.0.4 GUI Package Manager for Arch Linux Adds New Search Experience
Shelly 3.0.4 graphical package manager for Arch Linux distributions is now available for download with a new search experience, initial text-mode UI, improved AppImage integration, and more.
Bullying Women During Family Events and Holidays [original]
Rianne isn't easy to scare and she's practical like me
23 Years After GNU/Linux Was a Neglected Niche [original]
Is the movement finally bearing huge fruit?
GNU/Linux at 11% Globally [original]
Clownflare does not quite refute this
Free and Open Source Software
This is free and open source software
We Don't Need Search Engines and Social Control Media [original]
For many people it's just natural to visit us and we have RSS feeds
Election Tomorrow Has Daniel Pocock on the Ballot [original]
It's unlikely he'll win a seat, but he can win exposure
Today in Techrights
Some of the latest articles
GNOME Devs Share GNOME Shell Design Ideas for Future GNOME Releases
The GNOME design team talks about new search overlay, editable Quick Settings, transparent panel, Mosaic tiling, revamped window switching, login grid, dynamic batter icon, and more.