Microsoft moved to block VBA macros by default in Office files downloaded from the internet, targeting a long-running infection path used to deliver malware, phishing payloads, ransomware, and remote access tools. The change applies to Office on Windows for Access, Excel, PowerPoint, Visio, and Word, where internet-sourced macro-enabled files now show a Security Risk warning tied to Mark of the Web (MOTW) metadata instead of prompting users to enable content. After briefly rolling the change back following user feedback, Microsoft resumed rollout with updated guidance for users and administrators, who can still manage exceptions through Group Policy, Trusted Locations, and Trusted Publishers.
The decision follows repeated abuse of malicious Office documents in real-world campaigns. Fortinet documented a spam operation using Black Lives Matter lures and password-protected Word files to deliver TrickBot, while separate analysis showed a macro-enabled Word document using obfuscated VBA and doubly Base64-encoded PowerShell to fetch and run Remcos RAT. Researchers also warned that attackers can bypass MOTW-based protections by delivering documents inside container formats such as ISO files, where extracted files may lose the Zone.Identifier alternate data stream and be treated as local files, allowing macro execution unless additional controls such as Attack Surface Reduction rules are enforced.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced that VBA macros in Office files obtained from the internet would be blocked by default in Office on Windows for Access, Excel, PowerPoint, Visio, and Word. The company said the change was intended to reduce malware, phishing, ransomware, and remote access risks from malicious macros.
FortiGuard Labs discovered a global malicious spam campaign on June 10, 2020 that used Black Lives Matter-themed lures and password-protected Word documents to deliver TrickBot, primarily targeting users in Canada and the United States.
A malicious DOCM file used as a Remcos RAT dropper was first seen on May 27, 2020. The document used VBA macros and PowerShell to download and execute a next-stage payload from attacker-controlled infrastructure.
Microsoft resumed rollout of the default internet macro-blocking change in Current Channel and updated end-user and IT admin documentation, including guidance for files on SharePoint and network shares.
Microsoft temporarily rolled back the default blocking of internet-sourced macros after receiving user feedback and while making usability improvements.
Microsoft said rollout of the default macro-blocking change would begin in Version 2203 through Current Channel (Preview) in early April 2022, with later expansion to other update channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcecloudsek.com
Open sourcetechcommunity.microsoft.com
Open sourcegithub.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.