Malware embedded in document macros that executes when the document is opened with macros enabled.
Macro viruses are malware written in macro languages (like VBA in Microsoft Office) embedded within documents. When victims open infected documents and enable macros, the malicious code executes—downloading additional malware, stealing data, or compromising systems. Macro malware remains prevalent despite being a decades-old technique, delivered through phishing emails with malicious attachments. Microsoft has increasingly restricted macro execution, but attackers continue finding ways to convince users to enable them.
Why It Matters
The DSC Perspective:
Macro malware remains a primary initial access vector. Disabling macros by default, blocking macros in files from the internet, and user awareness training significantly reduce risk. Microsoft 365 provides policy controls for macro security.
