No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

How Cybercriminals Adapted to Microsoft Blocking Macros by Default

May 12, 2023
in Protection
0
How Cybercriminals Adapted to Microsoft Blocking Macros by Default



Ever since Microsoft decided to block Office macros by default, threat actors have been forced to evolve, adopting new methods for delivering malware at an unprecedented rate.

For a long time, threat actors have used malicious Microsoft Office macros to get a hook inside of their target’s computers. It was for that reason that, in 2022, Microsoft finally — though unevenly — began blocking macros by default on files downloaded from the Internet.

Now, without their favorite toy, hackers are having to come up with new ways to get their malware where they want it to go.

“In a lot of ways, they’re just kind of throwing spaghetti at the wall to see what sticks,” says Selena Larson, author of a new report on the trend. “The energy that they’re spending to create new attack chains is really unique,” and cyber defenders are going to have to keep up.

How Attackers Have Adjusted

Rarely has such a simple policy change made such a big difference in the cybercrime landscape. In 2021, the year of Microsoft’s announcement, researchers from Proofpoint tracked well beyond a thousand malicious campaigns utilizing macros.

In 2022 — the year the policy change took effect — macro-enabled attacks plummeted 66%. Thus far in 2023, macros have all but disappeared in cyberattacks.

In their place, hackers need some other solution. Container files emerged as a popular alternative last year, allowing attackers to bypass Microsoft’s “mark-of-the-Web” tag for files downloaded from the Internet. Once Microsoft addressed that workaround, however, such files went the way of the macro.

Since then, hackers have been searching for their new golden goose.

For example, in H2 2022, Proofpoint researchers observed a significant rise in HTML smuggling — slipping an encoded script through an HTML attachment. In 2023, good ol’ PDFs have proven a popular file format for attackers. And last December, some malicious campaigns began utilizing Microsoft’s notes-taking app OneNote as a means for delivering their malware. By January, dozens of threat actors piled onto the trend, and, in recent months, over 120 campaigns have made use of OneNote.

Nothing has stuck, though. “We haven’t seen anything that has the same type of durability as the macro-enabled attachment,” Larson says.

What This Means for Security Teams

“Attackers are having to be more creative now, which presents more opportunities for them to screw up or make mistakes,” Larson says.

Still, forcing cybercriminals out of their comfort zone comes with a cost. “The speed and the rate and scope of the changes that they’re making — all the different attack chains that they’re experimenting with — stands out,” she says.

And so, cyber defenders will have to move equally fast to keep up. “We’re having to be proactive to threat actor behavior and come up with new detections and rules and such, because threat actors are trying different ways to bypass existing detections,” she says.

Organizations, too, will need to keep up-to-date with the latest trends. Take security trainings: “I know that a lot of the time, people are trained on macro-enabled documents. Now you have to make your users aware of the new PDF methods and use real-world examples of potential threats to incorporate into security training,” she says.

“But from an overall, holistic security viewpoint, I don’t think there’s anything that needs to drastically change, as long as you are ensuring that users are aware,” Larson says. “Just being, like, ‘Hey, look out for this type of thing!'”



Editorial Team

Editorial Team

Related Posts

The Titanium Apple Watch Series 10 Is Just $449 During the Amazon Big Spring Sale
Protection

The Titanium Apple Watch Series 10 Is Just $449 During the Amazon Big Spring Sale

March 25, 2026
This Kindle Colorsoft (With Case) Is 40% Off During Amazon's Big Spring Sale
Protection

This Kindle Colorsoft (With Case) Is 40% Off During Amazon’s Big Spring Sale

March 25, 2026
Amazon's Prices on the Fire TV 4-Series Are Ridiculously Low During the Big Spring Sale
Protection

Amazon’s Prices on the Fire TV 4-Series Are Ridiculously Low During the Big Spring Sale

March 25, 2026
The Best Budget Treadmill Is Even Cheaper During Amazon's Big Spring Sale
Protection

The Best Budget Treadmill Is Even Cheaper During Amazon’s Big Spring Sale

March 25, 2026
These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale
Protection

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

March 25, 2026
The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale
Protection

The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale

March 25, 2026
Load More
Next Post
EV Start-Ups Like Polestar and Lucid Cut Production Estimates. Here's Why.

EV Start-Ups Like Polestar and Lucid Cut Production Estimates. Here's Why.

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0

Latest News

The 5 highest-paid college basketball players this year: No. 1 is making $4.2 million from NIL

The 5 highest-paid college basketball players this year: No. 1 is making $4.2 million from NIL

March 25, 2026
0

As the Sweet 16 of March Madness tips off, multiple athletes are now earning over $1 million from NIL deals.

The Titanium Apple Watch Series 10 Is Just $449 During the Amazon Big Spring Sale

The Titanium Apple Watch Series 10 Is Just $449 During the Amazon Big Spring Sale

March 25, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Ranjan Roy: OpenAI’s revenue could reach $284 billion by 2030, skepticism surrounds sustainability of growth projections, and Amazon’s retail model faces critical challenges

Ranjan Roy: OpenAI’s revenue could reach $284 billion by 2030, skepticism surrounds sustainability of growth projections, and Amazon’s retail model faces critical challenges

March 25, 2026
0

Key Takeaways OpenAI’s revenue has surged to $25 billion annually, reflecting robust growth in AI adoption. There is skepticism about...

Condé Nast Traveler

Where to Eat, Stay, and Play in Sacramento, California’s Increasingly Cool Capital

March 25, 2026
0

Where to eat in SacramentoSacramento's dining scene is shaped by two forces that don't always coexist: one of the most...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.