top of page
APT41 - HOODOO, Wicked Panda
Affects:

Severity:
HIGH
Productivity Impact:
VERY LOW
Fix Estimate:
2-3 minutes
Automatically protected by:

Research:
Summary:
APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.
Remediation details
Disable .CHM files as Email Attachments
Navigate to https://security.microsoft.com/
Click on Policies & Rules
Select Threat Poliicies
Select Anti-malware
Click Edit Protection Settings
Ensure common attachment filter is enabled
Click Select file type
Add .CHM
In addition to the above, there is an a more detailed guide you can leverage here: https://activedirectorypro.com/block-dangerous-file-attachments-in-exchange-online/
bottom of page