Cyber criminals pivot away from macros as Microsoft changes bite

General News

Summary

The use of malicious macros by cyber criminal groups has dropped a remarkable 66% since last October, and may now be one of the largest email threat landscape shifts in industry history, according to research data published28 July by Proofpoint. The shift is almost entirely down to Microsoft having decided to block Visual Basic for Applications (VBA) and Excel-specific XL4 macros across the Office suite in a series of policy changes dating back to last autumn. Although ISO and RAR files do have the MOTW attribute (because they were still downloaded from the internet), the document contained within will not, and when it is extracted, although the user will still have to enable macros for the malicious code to execute, their system will not spot the difference, leading to compromise. Microsoft has kept its counsel on the precise nature of the negative feedback it received, but in a note detailing the policy resumption, product manager Kelly Eickmeyer said: “We’ve made updates to both our end user and our IT admin documentation to make clearer what options you have for different scenarios. • Researchers at Proofpoint have discovered potentially dangerous Microsoft Office 365 functionality that they believe may give ransomware a clear shot at files stored on SharePoint and OneDrive.

Classifications

industries
HealthTech
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software SaaS Data Loss Prevention (DLP)

Linked Companies

Proofpoint
$1M to $5M
Microsoft
$1B+
ObserveIT
$10M to $25M
Malwarebytes Inc
$100M to $250M