Cybercriminals are bypassing Microsoft’s blocking of macros in its Office suite by using alternative files to host malware, according to Proofpoint’s Threat Research Team. The usage of macros in malware campaigns has decreased by around 66% between October 2021 and June 2022, following Microsoft’s introduction of macro-blocking features. However, threat actors are now using container files such as ISO and RAR attachments, and Windows Shortcut files to carry malware, with campaigns doing so rising nearly 175% during that period.

SuperCard X Android malware use stolen cards in NFC relay attacks
Android devices are being targeted by a new malware-as-a-service (MaaS) platform, SuperCard X. The malware uses NFC relay attacks to conduct fraudulent point-of-sale and ATM