Microsoft OneDrive a willing and eager 'ransomware double agent'

Discussion in 'other security issues & news' started by Rasheed187, Aug 13, 2023.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Shocking to see that many EDR's (corporate AV's) can easily be tricked!

    They should know better than to simply trust certain signed processes. Instead, they should be switching to a zero trust architecture, I'm sure they can figure this out without causing to many false positives.

    And about OneDrive, I would stay away from this crappy app, it somehow ruined my normal system folder structure, so now I got two documents, downloads and desktop folders, it's garbage! Never had this with Google Drive, and then I'm talking about the desktop apps.

    https://www.theregister.com/2023/08/10/microsoft_onedrive/
     
  2. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,100
    Location:
    Canada
    https://www.techradar.com/pro/micro...se-a-serious-security-threat-to-your-business

    So basically the target device would first have to be compromised for this OneDrive attack to be successfully pulled off. This is really nothing special and no different than any compromised device, where an attacker has freedom to do whatever they wish.
     
  3. Acadia

    Acadia Registered Member

    Joined:
    Sep 8, 2002
    Posts:
    4,366
    Location:
    US
    One thing that drove me crazy with OneDrive is that it made it so hard to backup my Documents. Microsoft wants you to store all your Docs in the Microsoft Cloud. I finally found the hidden setting that enabled me to simply Drag and Drop my Docs onto my other hard drives. My Docs still get stored automatically in the Cloud, against my wishes, but now my other hard drives have priority.
    Acadia
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I think the point that they try to make is that AV's shouldn't blindly trust all known processes on the system. Let's say you download some app that seems to be perfectly legit, so your AV won't alert about it. But once you launch this app, it will inject code into OneDrive and make it encrypt files, now that's a serious problem. A truly smart behavior blocker would notice that something is seriously wrong.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    OneDrive is crap, best thing to do is to disable it ASAP. I still don't understand how it messed up Windows Explorer on my system.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.