Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

Sometimes security breaches and hacking attacks come from the most unlikely of sources, even going so far as to utilize trusted applications to infect an endpoint or network. This is the case with a new phishing attack which uses the Calculator application that comes built-in with Windows in a very creative way. This is just one example of how hackers have been forced to innovate to combat the increasingly secure systems which businesses and users rely on today, and it should be a testament as to why you can never be too careful.

What is the Threat?

A security researcher who goes by ProxyLife on Twitter has reportedly discovered that there are several strains of malware and phishing attacks utilizing an outdated version of Microsoft’s Calculator application to find their way onto your network and launch their attacks—specifically the Windows 7 version of Calculator. The way that it works is that a cybercriminal tricks the user into downloading an ISO disc image which is disguised as a PDF or other similar file. This ISO contains a shortcut to an opened version of the Calculator application.

The Windows 7 Calculator can use what are called Dynamic Link Libraries in the same folder rather than defaulting to Windows’ system default libraries. The Calculator then runs the library, which is infected with malware. Later versions of Calculator do not have this capability, hence why an older version is necessary. Since Windows thinks that Calculator is a legitimate application, opening it in this way doesn’t set off any red flags within the system.

Should You be Worried?

At the end of the day, this is largely an obscure threat that sees hackers using the tools at their disposal in creative and different ways. It is not yet known if Microsoft has issued an update to Defender to put a stop to these types of attacks, but the long and short of it is that you probably won’t encounter this specific threat, as long as you are using proper security practices while browsing the Internet or checking your email.

Still, the idea that threats can use trusted and known applications in this way can make things a bit of a hassle for your IT team. These types of attacks might bypass the defenses built into your operating systems, but they can be caught if you are proactively monitoring your infrastructure for abnormalities. These abnormalities can then be contained, isolated, and eliminated. Of course, the problem here is that you likely wouldn’t find this type of threat if you weren’t actively looking for it—which is where we come in.

Proactively Monitor Your Network with Our Services

We know that it can be a challenge to keep your network safe. That’s why we make it easy with our remote monitoring services. Combined with comprehensive security solutions like a firewall, antivirus, spam blocker, and content filter, you’ll find that your network has never been safer. To learn more about what we can do for your business, contact us today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 26 July 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Efficiency Hardware Internet Malware IT Support Privacy Google Email Computer Workplace Tips Phishing Hosted Solutions IT Services Users Collaboration Mobile Device Workplace Strategy Ransomware Small Business Quick Tips Cybersecurity Microsoft Backup Communication Passwords Data Backup Saving Money Smartphone Managed Service Android Business Management VoIP Smartphones Mobile Devices communications Upgrade Disaster Recovery Data Recovery Browser Social Media Productivity Managed IT Services Microsoft Office Windows AI Current Events Remote Network Tech Term Internet of Things Facebook Automation Artificial Intelligence Cloud Computing Covid-19 Gadgets Holiday Information Miscellaneous Remote Work Training Server Managed Service Provider Outsourced IT Encryption Spam Employee/Employer Relationship Compliance Windows 10 Office Business Continuity Government Data Management Blockchain Virtualization Business Technology Wi-Fi IT Support Windows 10 Bandwidth Vendor Apps Two-factor Authentication Mobile Office Data Security BYOD Apple App Employer-Employee Relationship Managed Services Voice over Internet Protocol Mobile Device Management Networking Chrome Gmail Budget WiFi HIPAA Applications Access Control Computing Tip of the week Hacker Information Technology Avoiding Downtime Conferencing Marketing Office 365 How To BDR Storage Password Bring Your Own Device Big Data Router Virtual Private Network Health Operating System Help Desk Computers Risk Management Retail Website Healthcare Analytics Office Tips Managed IT Services Augmented Reality Patch Management Save Money Microsoft 365 Remote Monitoring The Internet of Things End of Support Vulnerability Vendor Management Solutions Social Physical Security Display Going Green Printer Windows 11 Paperless Office Infrastructure Monitoring 2FA Customer Service Cybercrime Excel Document Management Remote Workers Telephone Scam Data loss Cooperation Free Resource Firewall Project Management Windows 7 Safety Telephone System Multi-Factor Authentication Robot Mobility Cost Management Sports Mouse Administration IT Management VPN Employees Meetings Integration User Tip Modem Computer Repair Mobile Security Processor Customer Relationship Management Settings Holidays Wireless Printing Data Storage Content Filtering Smart Technology Supply Chain Hacking Video Conferencing Presentation YouTube Machine Learning Managed Services Provider Professional Services Cryptocurrency Saving Time Virtual Machines Wireless Technology Managed IT Service Maintenance Virtual Desktop LiFi Antivirus Downloads Data storage iPhone Licensing Word Outlook Vulnerabilities Entertainment Data Privacy Money Humor Images 101 Deep Learning Organization Travel Social Networking Legislation Shortcuts Google Maps Smart Devices Ransmoware Undo Techology Fileless Malware Digital Security Cameras Education Content Remote Working Wearable Technology Memory Vendors Comparison Google Play Be Proactive Health IT Unified Threat Management Motherboard Data Breach Assessment Electronic Health Records Permissions Workforce Mobile Computing Unified Threat Management Directions Videos Search Wasting Time Threats Network Congestion Specifications Security Cameras Workplace Strategies Application Best Practice Trend Micro Internet Exlporer Software as a Service Fraud Meta User Error Microchip Buisness IT solutions Username Managing Costs Amazon IBM Legal Black Friday SSID Business Growth Point of Sale eCommerce Database Surveillance Virtual Assistant Outsource IT Network Management Cortana Tech Support IT Technicians Virtual Machine Environment Media Monitors Cyber Monday Medical IT Alt Codes Proxy Server Reviews Cookies Tactics Development Hotspot Transportation Small Businesses Competition Downtime Hosted Solution Websites Mirgation Hypervisor Displays PowerPoint Typing Shopping Nanotechnology Optimization Addiction Electronic Medical Records Language Employer/Employee Relationships Outsourcing SharePoint User Management PCI DSS Knowledge Chatbots Navigation Google Drive Writing Distributed Denial of Service Workplace Lenovo Gig Economy Screen Reader Service Level Agreement Internet Service Provider 5G Virtual Reality Computing Infrastructure Teamwork Hiring/Firing Unified Communications Server Management Regulations Compliance Experience Private Cloud Identity Evernote Paperless IP Address Google Docs Co-managed IT Bitcoin Superfish Bookmark Running Cable Identity Theft Smart Tech Memes Download Net Neutrality Twitter Alerts SQL Server Technology Care Google Wallet Recovery Financial Data Error History Business Communications Social Engineering Break Fix Scams Hard Drives Windows 8 Browsers Smartwatch Laptop Connectivity IT Upload Procurement Remote Computing Azure Hybrid Work Domains Drones Social Network Telework Cyber security Multi-Factor Security Tech Human Resources Dark Web Cables Refrigeration CES Halloween Tablet IoT Communitications Trends Supply Chain Management Alert Public Speaking Lithium-ion battery Managed IT Customer Resource management FinTech File Sharing Regulations Dark Data Google Calendar Term Google Apps How To Microsoft Excel IT Maintenance Hacks Data Analysis Entrepreneur Scary Stories Star Wars IT Assessment Gamification Flexibility Fun Notifications Staff Value Business Intelligence

Blog Archive