Skip to main content

Hackers can now sneak malware into the GIFs you share

How low will malware go to get onto your device? We thought using Minecraft to gain access to your computer was the most nefarious method hackers have produced, but there’s a new, even lower type of attack that uses Microsoft Teams and GIFs to mount phishing attacks on your computer.

The new attack is called GIFShell and it installs malware on your computer to steal data. It does so by sneaking itself into innocent-looking GIFs and then waiting for you to share the GIF with your colleagues via Microsoft Teams.

A video call in progress on Microsoft Teams.

The problem was discovered by cybersecurity expert Bobby Rauch, who shared his findings exclusively with Bleeping Computers. This new GIF attack exploits multiple vulnerabilities in Microsoft Teams to create a chain of command executions.

The only thing the attackers need is a way to get into Microsoft Teams in the first place, and they have settled on one of everyone’s favorite web items: GIFs. The attacks include malicious code in base64 encoded GIFs. They then use Microsoft’s own web infrastructure to unpack the commands and install them directly on your computer.

Microsoft Teams is fairly secure and has multiple levels of protection against malicious file sharing. However, GIFs are usually benign, and people love sharing them. They’re the perfect conduit for attacks.

The files can spoof your computer into opening Windows programs such as Excel. It can then send data back to its originator by tricking Windows into connecting to a remote server.

Rauch disclosed his findings to Microsoft in May 2022, but the company has yet to fix the flaws. Microsoft told Bleeping Computers the GIF attacks “do not meet the bar for an urgent security fix.”

The best thing you can do for now is to not open any GIFs someone may share with you on Teams. We’ll keep an eye on this story and let you know when, and if, Microsoft gets around to fixing the vulnerability.

Nathan Drescher
Nathan Drescher is a freelance journalist and writer from Ottawa, Canada. He's been writing about technology from around the…
Surface repair parts are now available via Microsoft Store
Microsoft Surface Studio 2+ sitting flat on a table.

Microsoft has started selling replacement parts for its Surface devices in the Microsoft Store, making it easier for owners to repair their own machines.

Available components for Surface products include batteries, displays, cameras, kickstands, back covers, and speakers, among others.

Read more
If you have a Gigabyte motherboard, your PC might stealthily download malware
A Gigabyte Aorus Extreme motherboard.

Yet another motherboard manufacturer seems to be in trouble -- or rather, the people who own those motherboards might be. According to security researchers, countless Gigabyte boards might be vulnerable to dangerous cyberattacks.

If you want to be extra safe, there are a couple of things you can do to protect your PC. Here's what we know.

Read more
The 10 best ChatGPT Plugins you can use right now
OpenAI's website open on a MacBook, showing ChatGPT plugins.

ChatGPT is an amazing tool, but plugins make it even more so by unlocking a range of exciting new abilities. From booking a restaurant table for you to custom designing t-shirts based on your prompts, ChatGPT plugins are the future of AI chatbots. Until the next big thing comes along, at least.

Here are some of the best ChatGPT plugins you can use to leverage AI in ways you never even dreamed of.
How to use ChatGPT plugins
In order to run ChatGPT with plugins enabled, you need to be a ChatGPT Plus subscriber. It's $20 a month, but you get priority access to the chatbot so there's almost never any waiting, and you can also use advanced features like the GPT-4 language model, and play with the new web-search capabilities of ChatGPT.

Read more