Tux Machines

Do you waddle the waddle?

Other Sites

Internet Society

How One Alum Helped Build a Community of Internet Leaders

When Amged B. Shwehdy attended his first global Internet Governance Forum (IGF) in 2019, he expected to learn from the discussions shaping the future of the Internet. Instead, the experience revealed how little Libya was represented in those conversations.

The Tribal Broadband Bootcamps Celebrate Their Five-Year Anniversary

Arriving in the California desert to attend my first Tribal Broadband Bootcamp for the organization’s five-year anniversary celebration, I had the pleasure of sitting down next to a young woman who shared that she felt a bit out of place.

LinuxGizmos.com

Comu Fits a 144MHz CH32V203 RISC-V Board Inside a USB-A Port

Tindie recently listed Comu, a compact development board built around the WCH CH32V203 RISC-V microcontroller. Measuring 13 × 9.4mm, the board fits inside a USB-A port and combines programmable touch controls, LEDs, USB device support, and access to several GPIO signals.

NXP FRDM i.MX 95 Pro Pairs Six Cortex-A55 Cores with 8 eTOPS AI Acceleration

NXP has released the FRDM i.MX 95 Pro, a development board designed for evaluating the company’s i.MX 95 applications processor in edge AI, industrial networking, robotics, vision processing, and advanced HMI applications.

Raspberry Pi 4 3GB Variant Reaches More Distributors Following April Introduction

Raspberry Pi introduced a new 3GB version of the Raspberry Pi 4 Model B in April, positioning it between the existing 2GB and 4GB configurations. Four months after the announcement, the model is appearing through additional distributors, including TME, PiShop.us, and Waveshare.

9to5Linux

New Debian 13 Kernel Security Update Fixes “Zapscape” and “SCTPhantom”

The new Debian 13 “Trixie” kernel update addresses a total of 28 flaws, a smaller number compared to the 68 vulnerabilities patched in last week’s kernel security update. These new Linux kernel vulnerabilities may lead to privilege escalation, denial of service, or information leaks.

Calibre 9.13 E-Book Manager Improves PDF Output, Content Server, and More

Coming a week after Calibre 9.12, the Calibre 9.13 release only fixes bugs, including a regression in the PDF output from the Calibre 9 series that caused links in PDF files to scroll to a target location minus the top margin, which ended up being a few lines above the target.

news

Microsoft Windows 11 Caches Exploitable Malware

posted by Roy Schestowitz on May 15, 2024

Fishtank PC builds

Reprinted with permission from Cybershow. Author: Helen Plews.

Figure 1: Tom's Hardware: Fishtank PC builds.

Malware is often thought of as a human interaction with a digital device that causes an infection such as a virus or worm. We assume a human used bad authentication, or the human clicked the bad link, the human downloaded the malware…

So if we have anti-virus and anti-phish educational campaigns we should be well protected right? What about the technical side of cybersecurity, where the hardware, network equipment, end device or software vulnerability is the cause?

This article will examine a case where an operating system is able to automatically open and store a phishing email attachment, leading to potential compromise. In this case Windows 11 has been caching attachments locally to provide synchronisation across devices with the Outlook Application. In many cases, it has cached exploitable malware. This is a growing issue brought to light by Windows 11 users and anti-virus providers, instead of the makers at Microsoft.

Dropper Investigation

I am a life-long gamer and from experimentation over the years, I know I have the best rig, a customisable gaming PC. It’s very nice hardware it looks stunning with rainbow glowing fans and it sounds like a mini jet engine, rendering most graphics on Ultra with a graphics card which is at most 2 years old. The only issue I have had with it is in the operating system, which of course for a big gamer is Windows 11 due to its age. After just two weeks of operation I was alerted to a dropper located in my Windows Appdata folder, it was not dropping any further viruses yet as it had been caught by my expensive AV - which is why it sounds like a jet engine due to the large use of CPU!!

Was it a false positive? Well I ran the offline scan myself as my machine took 8x longer to boot. It behaved as if rebooting after a major update. There were no updates carried out, which made me suspect something amiss.

The virus location was not new to me, it is an appdata folder present in Windows 10 and Windows 11 for Windows mail in particular it processes mail syncing across devices; the full path is:

C:\Users\’Username’\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\SO\

Now I have had viruses popping up here before, in fact it has been an ongoing problem since I adopted the Windows 11 operating system (OS) in 2022 on the household laptops. Since then, both of my son’s laptops have alerted me to droppers and Trojans in the same Appdata folder. I initially assumed my children were not so good with their cybersecurity (being aged 5 and 9 that makes sense). Maybe they had clicked an email notification. Maybe they had downloaded some Trojan in the style of a game from a requested and shoddy gaming store all parents know about, stealthy and all whilst under supervision. That was until my brand new gaming rig got one.

Examining the attack timeline of my gaming rig in detail showed that a phish had been ‘clicked’ from my Hotmail account which was logged in on my Outlook App, running in the background processes (not running in my taskbar) whilst I played some epic title the night before. This ‘click’ put an infected PDF invoice on my PC, and on boot the next day activated the dropper, slowing the machine right down - which gave me a clue.

Now let's be clear about how Microsoft works, as I understand it, and why this is a gripe serious enough to warrant its own blog post.

You must sign in online to a Microsoft account to access the PC at all times, then it creates session keys for all applications that come installed as standard with the OS. So, unless you take some drastic measures I will discuss in a moment, you will undoubtedly be running sessions of Windows apps in the background; Outlook, OneDrive, Teams, Xbox, Photos, Office, Store, the list is quite extensive.

Moving on, I look for the phish email I had. According to my AV "clicked on" log, I located the suspicious subject of the email. It was something akin to;

AMAZON ACCOUNT ###U$IIHknDBWON38383y4y29~~~

Now, you do not need to be a cybersecurity expert to tell that is a phish from the subject which was located using the now foreground Outlook app. And as expected, it was unread. It showed me that within a few minutes of receiving the unread email, the attached PDF invoice was added to the Windows Communication Appdata folder, which led to the dropper found by the offline scan.

It seemed that Outlook App was saving unread attachments to the appdata folder where the virus was located. Some of the located viruses over the past two years were found on multiple devices that used the same MS credentials which unless stated otherwise, auto sync application data. That is exactly what the

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

folder is for. It contains both the application data for Windows apps like Outlook to run and sync as well as data obtained in the process. I synced between my children's laptops as my account was the administrator for the network, it kept them safer online. Or so I thought.

Vulnerability Research

So I start down the usual process of researching the vulnerability to find a permanent mitigation. I find nothing at first, no CVE, no reports. I do find some details on the MS community website like this one from "2020 Trojan Found and Deleted"… but it Returns (Trojan: HTML/Phish.AB!MSR) . It is here I see the same problem and I see a response from an expert.

“The trojan is an email attachment synced to your PC. Do you have some Hotmail or Microsoft email setup in an email client applications like Outlook?” - Independent Expert, MS Community, 2020

So I search all around this topic and I cannot find anything from Microsoft about this issue right away, but I do find many victims. Anti-Virus companies, affected users and experts alike are all drawing attention to this problem. Eventually, thanks to Reddit I find a similar experience from a commentor who managed to find the reported exploit listed by Microsoft. You can find many more threads on the issue on Reddit with a search.

“Looking into the report we have a "Exploit:O97M/CVE-2017-11882.AZA!MTB" match, which doesn't seem to be that ominous since it requires the file to be executed on a non-updated Office/WordPad, still it ain't something I'd like to find lying around because the app found it was a good thing to download it, without my consent.” - JVMTG, Reddit, 2023

It is a known software error marked as severe on their own security intelligence website, with 24 exploits under the O97M CVE. I’d like to say I have more details from Microsoft but I do not, instead they offer very little default cybersecurity steps, such as "remain up to date and don’t click a phish".

This does seem rather severe. It locally caches attachments from emails including those which have not been opened to the windowscommunicationsapps folder from the Outlook App. It will then auto sync the data in the folder to all devices using the same credentials in their Outlook App on their phones, laptops, desktops, anywhere the Outlook App runs.

The only step missing for a full compromise is that infected files are auto-run… a feature I feel sure Microsoft are working on at this exact moment!

Attacks are becoming more complex, in 2022 they were able to add the dropper, which very slowly downloaded a fairly rubbish Trojan, which was easily removed. Recently there were 74 password protected files and multiple Trojans appearing as game applications in the same appdata folder. These were located only weeks after a fresh OS install and could not be explained by known activities on the machine or entirely resolved by AV due to the encryption of the folders they were located in.

Impact

Take a moment to think about how many commercial users of the Outlook application have auto-sync enabled in daily use. All those using Office 365 who sync between devices on their smartphone, personal devices and company equipment, or amongst family member's tablets and laptops. You should be concerned. And then get mad as hell, because it seems Microsoft have created their own quite special service for propagating malware, one that's been ongoing since at least 2020.

I have wasted countless hours re-installing OS’s, searching files, reading reports and researching this issue to find my only salvation in Reddit. Reddit of all places! This looks like something Microsoft rather wanted to sweep under the rug.

If you sync with Outlook App between devices with the same MS account, you are vulnerable to this malware propagation. Microsoft insist users take advantage of auto-synced features across devices and use this as a clear marketing tool especially for commercial settings. It seems my trust in this feature was misplaced.

Mitigation And Loss of Trust

Some will say that this is "just a feature" of sync. I disagree because like so many Microsoft processes it feels out of control. It does not just synchonise expected user data. It inappropriately populates and copies undocumented files into system folders and, without any knowledge or intervention from the user, replicates them across devices.

The mitigation is you must live without synchronisation in Microsoft applications. So far it has worked 100%. Turning off sync across applications does work. This can be done during an OS install by refusing all sync options when prompted. You must also make sure it is off in the account settings for the user. This can be done from the settings panel when logged on to Windows. There are many guides available like this one from Process.st. Even with sync off, you can still access email and other services using the web applications, which will sync files and emails but will not store these to the local machine.

If like myself, you have lost trust in the applications themselves, removing windows apps entirely may be more fitting, this allows the folder

microsoft.windowscommunicationsapps_8wekyb3d8bbwe

to be deleted and does not appear, like a lurking background threat at a later date just in case you change your mind. My gaming rig has only one MS app remaining, Xbox and that is the way it will stay until the situation is openly discussed by MS and the vulnerability resolved. No more Appdata Phishes please.

In summary, no amount of phishing training will prevent a bad design in the operating system. Caching malware infected attachments to system folders and replicating them is bad design in my opinion. In this case, the operating system has been phished, not the human.

Other Recent Tux Machines' Posts

Mesa 26.2 Open-Source Graphics Stack Officially Released, Here’s What’s New
Mesa 26.2 open-source graphics stack is now available for download with new features and improvements across all supported drivers. Here’s what’s new!
Fear, Uncertainty, Doubt: Microsoft Pundit Calls "Linux" Users "AI" Because the Data Looks Bad for Windows
as usual
 
Android Leftovers
After trying wired Android Auto I'm never going back to wireless
Free and Open Source Software
This is free and open source software
Linux Surpasses Double-Digit Market Share
According to two sources, the Linux operating system has hit a major milestone in market share that naysayers thought would never happen
This Week in Plasma: UI Improvements Galore
This week we merged a number of features and UI changes that focus on user-friendliness
Getting serious with /e/OS - Hurdles and obstacles
At the moment, my choice seems to be the Fairphone, with /e/OS
NetHydra 1.1.0 Release
(Root, Desktop changes)
Mobile OS Release: Murena 4.1.1
v4.1.1-a16
Stable kernels: Linux 6.12.102, Linux 6.6.150, Linux 6.1.182, Linux 5.15.215, and Linux 5.10.264
I'm announcing the release of the 6.12.102 kernel
No Human, No Copyright: The Legal Risk of Vibe‑Coded Software
In other words, just because you described it doesn’t mean you have any claim to the copyright
Today in Techrights
Some of the latest articles
New Debian 13 Kernel Security Update Fixes “Zapscape” and “SCTPhantom”
A new Linux kernel security update has been released for Debian GNU/Linux 13 “Trixie” to fix 28 security vulnerabilities in Linux 6.12 LTS. Update as soon as possible!
Billions of Sessions' Web Survey: GNU/Linux at 7% [original]
Days ago it said 6.4%, now it's up to 6.8%
GNU/Linux Desktop Share More Than Doubled in a Year in Guam [original]
That seems to be changing this year
Next Week It'll be 3 Months of Shell Tank [original]
Today ends the first week of August
Signing Off for a Bit [original]
We already average at about 35 new pages per day
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Free Software, Digital Sovereignty, and Standards
FOSS and more
WordPress 7.0.3 is Out, "I Built a Blog and Forgot to Write"
blogging news
Programming Leftovers
Development picks
GNOME: Icon for KawaiiFi and Sovereign Tech Fellowship for GNOME Design & Community Management
GNOME aesthetics
Open Hardware/Modding: Arduino, Raspberry Pi, and More
Hardware leftovers
Games: DRM-free, MECCHA CHAMELEON, and More
GamingOnLinux articles
Dual Booting Done Wrong, or How Microsoft Has Made It Harder to Boot Into GNU/Linux
2 articles
Red Hat: Paid-for SPAM (Disguised as Recommendations and Journalism), US Army, Slop Plagiarism, and More
shallow coverage/blog posts
Security Leftovers
Security breaches, patches, and more
today's howtos
Instructionals/Technical picks
'Linux' Foundation on Linux Vendor Firmware Service (LVFS), Revisionism (GNU/Linux Started in 1983), and Promotion of Slop Plagiarism Using the "Linux" Brand
LF leftovers
Kernel: Linux Plumbers 2026, Concerns About Slop Disrupting Developers' Workflow, Aarch64, GNU Hurd Reemerges
kernel news
Audiocasts/Shows: Internet Archive and BSD Now
2 new episodes
Desktop/Laptop: EU’s Age Verification, Old PCs, Trying GNU/Linux, and "Linux Use Surges in North America"
4 new stories
Could your old computer have a second life?
Security matters here as well. Because Linux is built differently, it is targeted far less often by malware and ransomware
Why some tech users are ditching Android for Linux phones
Because SailfishOS is built on Linux, users can SSH into the phone from a PC, either wirelessly or over USB, to troubleshoot or tinker
Android Leftovers
Google Rolls Out August Android 17 Update With Pixel 10 Stability Fixes
250 Billion Euros Wasted on Proprietary Stuff (Mostly American) Instead of Investing in Local IT Talent and Free (Libre) Code [original]
Will Europe realise that GAFAM is a risk, not a suitable "IT provider"?
Your favorite Linux distro probably descends from one of these three operating systems
Trace the ancestry of many Linux distributions still in widespread use
After Nearly a Decade of Distro Hopping, I Realized It Was Never About the Distro
For years I thought I had strong opinions on Linux distros. Ubuntu was too heavy or it felt
Free and Open Source Software, and Review
This is free and open source software
Stable kernels: Linux 7.1.7, Linux 6.18.43, Linux 6.6.149, Linux 6.1.181, Linux 5.15.214, and Linux 5.10.263
I'm announcing the release of the 7.1.7 kernel
Today in Techrights
Some of the latest articles
Calibre 9.13 E-Book Manager Improves PDF Output, Content Server, and More
Calibre 9.13 open-source ebook manager is now available for download as a bugfix release that addresses various regressions introduced in the previous release and other issues.
GNU/Linux and BSD Leftovers
mostly GNU/Linux
Tails 7.10.1 Is Out as an Emergency Release to Fix Critical Vulnerabilities
Tails 7.10.1 anonymous Linux distribution is now available for download as an emergency point release to Tails 7.10 to fix critical vulnerabilities.
Canonical/Ubuntu: Resources, Multipass, MAAS, and MicroCloud
Some Ubuntu centric stuff
Open Hardware and Linux Mobile
Open Hardware news for the most part
Web Browsers/Web Servers/Feed Readers Leftovers
WWW related picks
Content Management Systems (CMS) / Static Site Generators (SSG): WordPress 7.1 Release Candidate 1, powRSS, and More
Web platforms
GenOffice and LibreOffice Introduced or Summarised (Monthly Report)
some alternatives to GAFAM
Programming and Standards
mostly coding related picks
GNOME: Enrico Zini Cannot Sleep, Icon for Lockpicker
GNOME picks
A KDE Summer 2026 Update and "Akademy 2027 Call for Hosts"
KDE picks
IBM, Fedora, and Red Hat's Mindless, Endless Promotion of Microsoft and Slop
IBM stuff
Openwashing by Microsoft OSI, "Linux" Brand Misused by Jim Zemlin (Not a Linux User) to Promote Slop Plagiarism, Grifting, Even False History
"Linux" and GAFAM don't mix well
Security and Microsoft TCO
leftovers regarding Microsoft TCO and breaches, patches...
"Desktop Linux just cracked 10% market share"
Even ZDNet and IDG say..
RPCS3 Sees GNU/Linux at 6%
new RPCS3 data
Kernel: Issues With Slop Noise, Linux Plumbers Conference, Virtualisation, and More
leftovers and Linux picks
Rhythmbox 3.5 Media Player Improves Lyrics Search and Podcast Support
Rhythmbox 3.5 open-source media player is now available for download with improvements to lyrics search, podcast support, and the new playback backend. Here’s what’s new!
Linux Magazine Issue 310
partially paywalled
GNU/Linux Near 13% in Fiji [original]
Years ago GNU/Linux was negligible (sub-1%), now it fluctuates around 5-10%, sometimes higher
3-Week Semi-Break From the Routine [original]
Some time next year we definitely plan to show how the EFF failed women, failed bloggers, and basically prioritised GAFAM
It's Global Warming, Stupid, Not Just Irresponsible Zoos [original]
This is a man-made problem, an avoidable problem
today's howtos
Instructionals/Technical picks
Games: Prison Architect, Half-Life 2: VR Mod, Easy Anti-Cheat (Rootkit)
latest from GamingOnLinux
I rebuilt my home servers from scratch, and this is the OS setup I wish I'd started with
It was Ubuntu Server, something I had extensive history and experience using
I stopped recommending Bazzite after realizing any Linux distro can game just as well
If you game on Linux or plan to at all in the future, these updates were some of the most consequential things to happen in the last month with regard to your PC's future
My new favorite way to run Linux has nothing to do virtualization
I love using Linux. I love jumping between different distributions (although I have come to prefer Arch) and trying out new desktop environments
Desktop Linux apps on Android proved my phone's biggest bottleneck isn't what I thought
Running desktop Linux apps on an Android phone sounds like the sort of thing that should fall apart almost immediately
Virtual machines are the easiest way to try Linux without causing unnecessary headaches
Having felt this itch, I started to dip my toes into the world of Linux over a year ago
RPCS3 recommends this Linux distro for best PS3 emulation
PlayStation 3 emulator RPCS3 works the best on Linux
4 reasons why Linux will be king in 2027
Your Windows machine wants to be your friend, but behind your back it tells Microsoft everything you do
Want a free Photoshop alternative on Linux? How to get Affinity today: 2 ways
One method is easier, but the other gets you faster, more reliable performance
Potions in Mageia. 01 – Pidgin and its accessories
We started a series of blog posts. Ideas, applications, processes, customizations, contributions about our distribution that are relevant to our users
The Future of GNOME Boxes
I have spent the last two years rebuilding GNOME Boxes from the ground up
GNOME 50.4 Desktop Environment Released with Various Improvements
GNOME 50.4 is now available as the fourth point release to the latest GNOME 50 desktop environment series with more bug fixes, updated translations, and other changes.
Free and Open Source Software
This is free and open source software
Purism: Making Videos With Absolute Freedom
As with every video that we make at Purism, we have made the Librem 16 launch video in house with Librem hardware running PureOS
Burkina Faso: GNU/Linux Measured Near 20% [original]
Burkina Faso is a massive country and a lot of GNU/Linux is detected there
Most Humans Are Women, Why Not in Free Software Too? [original]
It is not that "women aren't good at maths"
5% of Desktops/Laptops of the Dominican Republic Run GNU/Linux Now? [original]
people replacing Windows with GNU/Linux
Relaxing Weeks Ahead [original]
We expect many news sites will "wind down" for the summer
Android Leftovers
Your Android keyboard remembers more than you realize — here's where it all goes
This gorgeous KDE icon pack gives your desktop a chalk-like look
One of the biggest things I love about Linux is that it's very customizable
Over 10% Market Share in Desktops and Laptops [original]
In desktops and in laptops GNU/Linux has become a big player
KDE Plasma 6.7.4 Is Out to Improve Spectacle, Discover, and Emoji Selector
KDE Plasma 6.7.4 is now available as the fourth maintenance update to the KDE Plasma 6.7 desktop environment series with more improvements and bug fixes.
Free and Open Source Software, howtos and Installations
This is free and open source software
Brett Wilson LLP Facilitated Abuse of Process for Balabhadra (Alex) Graveley and Matthew J. Garrett, So I am Suing Them in the High Court [original]
Half a decade ago Balabhadra (Alex) Graveley from Microsoft and GNOME was arrested for strangulation in Texas
LWN Articles About Linux Kernel
Kernel articles outside paywall, 5 in total
Today in Techrights
Some of the latest articles