Voyage Tech Blogs

Voyage Technology has been serving the Beaver Dam area since 1999, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

A Windows Vulnerability found in your Calculator? Here’s What You Should Know

Sometimes security breaches and hacking attacks come from the most unlikely of sources, even going so far as to utilize trusted applications to infect an endpoint or network. This is the case with a new phishing attack which uses the Calculator application that comes built-in with Windows in a very creative way. This is just one example of how hackers have been forced to innovate to combat the increasingly secure systems which businesses and users rely on today, and it should be a testament as to why you can never be too careful.

What is the Threat?

A security researcher who goes by ProxyLife on Twitter has reportedly discovered that there are several strains of malware and phishing attacks utilizing an outdated version of Microsoft’s Calculator application to find their way onto your network and launch their attacks—specifically the Windows 7 version of Calculator. The way that it works is that a cybercriminal tricks the user into downloading an ISO disc image which is disguised as a PDF or other similar file. This ISO contains a shortcut to an opened version of the Calculator application.

The Windows 7 Calculator can use what are called Dynamic Link Libraries in the same folder rather than defaulting to Windows’ system default libraries. The Calculator then runs the library, which is infected with malware. Later versions of Calculator do not have this capability, hence why an older version is necessary. Since Windows thinks that Calculator is a legitimate application, opening it in this way doesn’t set off any red flags within the system.

Should You be Worried?

At the end of the day, this is largely an obscure threat that sees hackers using the tools at their disposal in creative and different ways. It is not yet known if Microsoft has issued an update to Defender to put a stop to these types of attacks, but the long and short of it is that you probably won’t encounter this specific threat, as long as you are using proper security practices while browsing the Internet or checking your email.

Still, the idea that threats can use trusted and known applications in this way can make things a bit of a hassle for your IT team. These types of attacks might bypass the defenses built into your operating systems, but they can be caught if you are proactively monitoring your infrastructure for abnormalities. These abnormalities can then be contained, isolated, and eliminated. Of course, the problem here is that you likely wouldn’t find this type of threat if you weren’t actively looking for it—which is where we come in.

Proactively Monitor Your Network with Our Services

We know that it can be a challenge to keep your network safe. That’s why we make it easy with our remote monitoring services. Combined with comprehensive security solutions like a firewall, antivirus, spam blocker, and content filter, you’ll find that your network has never been safer. To learn more about what we can do for your business, contact us today at 800.618.9844.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Friday, 25 April 2025

Captcha Image

Sign Up For Our Newsletter!

Mobile? Grab this Article!

Qr Code

Tag Cloud

Security Technology Tip of the Week Best Practices Business Computing Data Productivity Business Software Innovation Hackers Cloud Network Security User Tips Hardware Internet Efficiency IT Support Malware Privacy Google Email Workplace Tips Phishing Computer IT Services Collaboration Hosted Solutions Users Mobile Device Ransomware Workplace Strategy Quick Tips Cybersecurity Small Business Microsoft Passwords Communication Data Backup Smartphone Backup Saving Money Business Management VoIP Smartphones Android Upgrade Managed Service Mobile Devices communications Disaster Recovery Data Recovery Browser Social Media Managed IT Services Microsoft Office Windows Remote Network Tech Term Internet of Things Current Events Artificial Intelligence Facebook Automation Productivity Covid-19 Cloud Computing Gadgets Server AI Managed Service Provider Remote Work Miscellaneous Outsourced IT Information Holiday Employee/Employer Relationship Encryption Spam Compliance Windows 10 Office Government Data Management Business Continuity Training Blockchain Windows 10 Bandwidth Virtualization Business Technology Wi-Fi Two-factor Authentication Mobile Office Data Security Apps Networking Mobile Device Management Chrome Gmail Budget BYOD Vendor Apple Managed Services App Voice over Internet Protocol Employer-Employee Relationship Avoiding Downtime Marketing How To Office 365 BDR IT Support WiFi Applications Access Control Tip of the week Computing Conferencing Hacker Information Technology Website Managed IT Services Office Tips Analytics Augmented Reality Storage Password HIPAA Router Bring Your Own Device Big Data Virtual Private Network Health Healthcare Help Desk Operating System Computers Retail Risk Management Scam Data loss Microsoft 365 Solutions Cooperation Firewall Patch Management Save Money Remote Monitoring End of Support Vulnerability Windows 11 Vendor Management 2FA The Internet of Things Physical Security Excel Display Printer Social Paperless Office Infrastructure Remote Workers Going Green Monitoring Document Management Customer Service Cybercrime Free Resource Project Management Windows 7 Telephone Multi-Factor Authentication Mobility Licensing Virtual Desktop Entertainment Data storage LiFi Word Outlook Employees Integration Robot Money Telephone System Cost Management Humor Holidays Safety Sports IT Management Meetings Mouse Data Storage VPN Supply Chain Video Conferencing Modem Administration User Tip Managed Services Provider Processor Virtual Machines Professional Services Computer Repair Mobile Security Smart Technology Customer Relationship Management Settings iPhone Printing Wireless Machine Learning Content Filtering Saving Time Hacking Vulnerabilities Presentation YouTube Data Privacy Managed IT Service Images 101 Cryptocurrency Maintenance Downloads Wireless Technology Antivirus Experience Connectivity Shortcuts Social Engineering Break Fix IP Address Google Docs Organization Unified Communications Browsers Digital Security Cameras Bitcoin Smart Devices Running Cable Upload Ransmoware Remote Computing Multi-Factor Security Google Wallet Remote Working Social Network Memory Vendors Data Breach Tablet IoT Google Play Be Proactive Dark Web Recovery Videos Hard Drives Windows 8 Electronic Health Records Laptop Trends Workforce Alert File Sharing Regulations Dark Data Google Calendar Domains Drones Managed IT Customer Resource management Wasting Time Threats Data Analysis Trend Micro Star Wars Security Cameras Workplace Strategies How To Microsoft Excel Refrigeration Software as a Service Halloween Gamification Meta Notifications Staff Travel Social Networking Legislation Public Speaking Managing Costs Amazon Techology Fileless Malware eCommerce Google Maps SSID Lithium-ion battery Hacks Surveillance Entrepreneur Scary Stories Content Virtual Assistant Outsource IT Wearable Technology Unified Threat Management Motherboard Media Comparison Health IT Virtual Machine Environment Fun Unified Threat Management Directions Assessment Medical IT Permissions Reviews Deep Learning Undo Development Transportation Small Businesses Network Congestion Specifications Education Hypervisor Displays User Error Microchip Optimization Internet Exlporer PowerPoint Fraud Shopping Mobile Computing Username Employer/Employee Relationships Outsourcing Point of Sale Navigation Black Friday PCI DSS Search Application Best Practice Database Workplace Gig Economy Internet Service Provider Buisness Network Management Teamwork Hiring/Firing Tech Support IT Technicians Cookies Evernote Paperless Monitors Cyber Monday IBM Legal Regulations Compliance IT solutions Proxy Server Business Growth Memes Tactics Co-managed IT Hotspot Net Neutrality SQL Server Technology Care Websites Mirgation Cortana Nanotechnology Business Communications Financial Data History Alt Codes SharePoint IT Addiction Scams Electronic Medical Records Language Smartwatch Competition Procurement Downtime Management Azure Hybrid Work Chatbots Screen Reader Tech Human Resources Writing Distributed Denial of Service Telework Hosted Solution Lenovo Cyber security Typing Communitications Service Level Agreement Cables Virtual Reality Computing Infrastructure CES Supply Chain Management Server Management Private Cloud Identity Knowledge Identity Theft Smart Tech Term Google Apps Google Drive FinTech User Superfish Bookmark IT Assessment Download IT Maintenance Twitter Alerts Flexibility Value Business Intelligence 5G Error

Blog Archive