Skip to main content

Hackers can now sneak malware into the GIFs you share

How low will malware go to get onto your device? We thought using Minecraft to gain access to your computer was the most nefarious method hackers have produced, but there’s a new, even lower type of attack that uses Microsoft Teams and GIFs to mount phishing attacks on your computer.

The new attack is called GIFShell and it installs malware on your computer to steal data. It does so by sneaking itself into innocent-looking GIFs and then waiting for you to share the GIF with your colleagues via Microsoft Teams.

A video call in progress on Microsoft Teams.
Image used with permission by copyright holder

The problem was discovered by cybersecurity expert Bobby Rauch, who shared his findings exclusively with Bleeping Computers. This new GIF attack exploits multiple vulnerabilities in Microsoft Teams to create a chain of command executions.

Recommended Videos

The only thing the attackers need is a way to get into Microsoft Teams in the first place, and they have settled on one of everyone’s favorite web items: GIFs. The attacks include malicious code in base64 encoded GIFs. They then use Microsoft’s own web infrastructure to unpack the commands and install them directly on your computer.

Microsoft Teams is fairly secure and has multiple levels of protection against malicious file sharing. However, GIFs are usually benign, and people love sharing them. They’re the perfect conduit for attacks.

The files can spoof your computer into opening Windows programs such as Excel. It can then send data back to its originator by tricking Windows into connecting to a remote server.

Rauch disclosed his findings to Microsoft in May 2022, but the company has yet to fix the flaws. Microsoft told Bleeping Computers the GIF attacks “do not meet the bar for an urgent security fix.”

The best thing you can do for now is to not open any GIFs someone may share with you on Teams. We’ll keep an eye on this story and let you know when, and if, Microsoft gets around to fixing the vulnerability.

Nathan Drescher
Former Digital Trends Contributor
Nathan Drescher is a freelance journalist and writer from Ottawa, Canada. He's been writing about technology from around the…
Microsoft says you can run DeepSeek R1 right on your laptop
The Surface Laptop shown in front of a Copilot+ sign.

Microsoft has made an interesting move in being quick to support the DeepSeek R1 reasoning model on its Azure cloud computing platform and GitHub tool for developers, not long after setting its sights legally on the China-based company.

Microsoft has announced that it will make the new DeepSeek AI model available in “NPU-optimized” versions that will be more aligned with Windows 11 Copilot+ PCs and compatible with the components they run. It will first roll out a version for Qualcomm Snapdragon X devices, then one for Intel Lunar Lake PCs, and finally a variant for AMD Ryzen AI 9 processors. Additionally, Microsoft will add the DeepSeek-R1-Distill-Qwen-1.5B model to its Microsoft AI Toolkit for developers, and will also make available 7B and 14B versions.

Read more
FBI to ‘remove’ this nasty malware that’s affected 2.5 million PCs
An individual surrounded by several computers typing on a laptop.

A malware originating from China has now been contained after the FBI gained a court order to have the harmful code deleted from thousands of Windows PCs.

The agency has successfully put an end to the reign of the PlugX malware in the U.S., which has affected over 2.5 million devices globally by infiltrating infected USB drives, PCMag noted.

Read more
You can now try out ChatGPT Search for free
The ChatGPT Search icon on the prompt window

As part of its "12 Days of OpenAI" event, OpenAI has yet another update for ChatGPT, this time bringing its Search feature over to the free tier. The Google Search alternative was previously only for paid subscribers in the ChatGPT Plus or Pro tiers.

"We rolled it out for paid users about two months ago," Kevin Weil, OpenAI's chief product officer, said during Monday's livestream. "I can't imagine ChatGPT without Search now. I use it so often. I'm so excited to bring it to all of you for free starting today."

Read more