Threat researchers reported that cybercriminals increasingly used Microsoft OneNote documents in phishing campaigns to deliver malware after Microsoft began blocking macros by default. Campaigns observed across North America, Europe, and other regions used OneNote attachments or links to .one files to distribute payloads including AsyncRAT, Qbot, RedLine, AgentTesla, Quasar RAT, XWorm, NetWire, and DOUBLEBACK. In the observed infection flow, victims had to open the OneNote file, double-click an embedded object disguised behind a lure image, and then approve a warning prompt before the malicious script or executable launched.
Detailed analysis of one phishing-themed sample, PaymentAdv.one, showed the document dropping an obfuscated batch file, zoo1.bat, which executed heavily obfuscated PowerShell to decrypt embedded payloads. Researchers found the script split a base64-encoded encrypted blob into data, an AES key, and an index, then decrypted and gzip-decoded it to recover executables; one recovered payload was a .NET binary packed with AgileDotNet and later identified, after unpacking and deobfuscation with de4dot, as AsyncRAT. Proofpoint also linked renewed TA577 activity to OneNote-delivered Qbot and noted that some OneNote malware samples had low antivirus detection when first analyzed.

Get the infrastructure and lures behind it.
9 events from the most recent confirmed update back to the earliest known activity.
On 31 January 2023, Proofpoint observed TA577 return from a month-long hiatus and use a OneNote-based infection chain to deliver Qbot. The campaign used URLs leading to a zipped OneNote file.
Also on 19 January 2023, Proofpoint observed a low-volume thread-hijacking campaign distributing the DOUBLEBACK backdoor through a ZIP archive containing a OneNote file. The lure executed an embedded VBS file that downloaded a PowerShell script to run DOUBLEBACK.
On 19 January 2023, Proofpoint observed two campaigns using URLs to deliver OneNote files that led to XWorm and DOUBLEBACK payloads. The campaigns reflected broader experimentation with OneNote-based delivery methods.
Proofpoint first observed Netwire being delivered through a OneNote campaign on 12 January 2023. This added another RAT family to the growing set of malware using the technique.
On 11 January 2023, Proofpoint first observed OneNote campaigns delivering Redline and AgentTesla. The finding showed continued diversification of payloads in these email-borne attacks.
Proofpoint first observed OneNote-delivered campaigns distributing Quasar RAT and XWorm on 9 January 2023. This marked an expansion in the malware families being delivered through OneNote lures.
In mid-January 2023, Proofpoint observed threat actors using URLs to deliver OneNote files instead of only attaching them directly to emails. The execution chain remained the same, still relying on users opening the file and interacting with embedded content.
Proofpoint observed six OneNote attachment campaigns in December 2022 that delivered AsyncRAT. Some December campaigns used invoice, shipping, aerospace, and holiday-themed lures to target organizations including manufacturing, industrial, and education sectors.
Researchers reported that attackers started using malicious Microsoft OneNote documents as a malware delivery mechanism in December 2022. Early campaigns delivered malware such as AsyncRAT and used embedded files hidden behind lure graphics that required user interaction to execute.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.