Software

They show how OneDrive is insecure against malware attacks

Microsoft OneDrive, one of the most popular cloud backup services because it comes pre-installed on Windows, could pose a serious security threat to businesses . In his presentation at the recent Black Hat conference, SafeBreach expert Or Yair demonstrated how threat actors could leverage the cloud storage platform for a ransomware attack.

The problem appears to be that OneDrive has an application that installs on Windows devices and looks like a folder . Users can access it locally through File Explorer, just like any other folder. The application also automatically syncs all the files stored in that folder with their corresponding copy in the cloud.

OneDrive doesn't seem to have good security, especially for businesses

The application also stores all user logs in a single directory . These logs contain session tokens that a cracker can extract from OneDrive directories and use to create junctions that lead to areas outside the OneDrive directory itself. This grants access to files stored locally on the target endpoint.

From there, all that was needed to complete the attack was to encrypt the files. Even those stored on OneDrive, which act as a shadow backup, were deleted. This is due to a vulnerability found in the OneDrive Android app . Once the app has finished, all the victim has are encrypted backups of the encrypted files. This is a way to fall victim to ransomware and be unable to recover the data.

skydrive onedrive

Most endpoint detection and response tools failed to detect the malicious application . And since no malicious code was added anywhere, they couldn't flag it as ransomware or malware either. CyberReason, Microsoft Defender for Endpoint, CrowdStrike Falcon, and Palo Alto Cortex XDR all failed the test. SentinelOne detected the attack but didn't stop it because OneDrive had been added to its allowlist.

To fix the problem, Microsoft has already released a patch, and all the aforementioned cybersecurity companies have patched their EDRs. However, to carry out the attack, the threat actor needs prior access to the target device . This means that if the computer isn't infected, there wouldn't be any problems, but once a malicious actor gains access, they can execute the attack.

Source: TechRadar

Show more

Benjamin Rosa

Madrileño whose publishing career began in 2009. I love investigating curiosities that I later bring to you, readers, in articles. I studied photography, a skill that I use to create humorous photomontages.

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.