Lead Image © Daniela Mangiuca, 123RF.com

Lead Image © Daniela Mangiuca, 123RF.com

Countering embedded malware attacks

The Return of the Macro Virus

Article from ADMIN 35/2016
By
With the resurgence of sophisticated macro virus attacks, new countermeasures are in order. We offer a few recommendations.

Embedded malware hidden as macros in Office documents, which automatically launch on opening, was extremely popular 15 years ago. To counter this, in 2001, Microsoft introduced a security policy in Office XP that prompted the user to decide whether or not to run code embedded in documents. This made macro virus attacks difficult to perform, so that other propagation paths became far more lucrative. Consequently, in the last few years, this form of malicious code has been almost completely forgotten, not least because manufacturers by default disabled macros in their products.

However, a Microsoft study from early 2015 shows evidence of a return of the macro virus. According to reports, within a very short time, more than 500,000 systems were infected by malware distributed in email spam. Today, macro viruses are again on the rise.

Hidden in Office Files

A macro virus is a piece of malicious code that exists as a standalone executable program but is embedded as a macro in a document. A macro can perform certain tasks automatically; it is used to perform malicious actions, such as installing more malicious code. Files that contain a macro virus and distributed via email are usually designed so that they appear inconspicuous to the receiver. Most users typically open invoices, reminders, and application documents without much thought.

Because macros are now disabled by default (Figure 1), many of these malicious files now contain step-by-step instructions for enabling macros. By suggesting that they would otherwise be unable to open and read the document, the recipient is thus lured into allowing the execution of macros. Additionally, targeted social engineering is used to pique the interest of the victims, and targeted attacks are performed on large groups of people and companies – often using file names such as

...
Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

comments powered by Disqus
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs



Support Our Work

ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.

Learn More”>
	</a>

<hr>		    
			</div>
		    		</div>

		<div class=