The figures that show why Microsoft is so worried about Office macros


New ransomware figures from Venafi and Forensic Pathways have shed some light on to why Microsoft is currently so worried about the security of Office macros.
Over the course of five months (November 2021 to March 2022), the two companies analyzed 35 million dark web URLs, including marketplaces and forums for ransomware products and services, finding that almost all (87%) of the ransomware found on the dark web has been delivered to endpoints via malicious macros.
The two companies identified a total of 30 different malware products, including Babuk, GoldenEye, Darkside/BlackCat, Egregor, HiddenTear, and WannaCry.
Macros as a ransomware launchpad
Not all ransomware was created equal, however. Those used in high-profile attacks cost more so, for example, the Darkside variant used in the Colonial Pipeline attack cost $1,262. Source code for popular ransomware is also relatively expensive, the researchers found, with Babuk’s source code going for $950, while Paradise’s sold for $593.
Macros are an important feature for every advanced Office user, as they allow the files to pull data from the web, automatically, and update the contents autonomously. Given the nature of the tool, it was being abused by threat actors for years, until Microsoft decided to prevent macro-carrying files downloaded from the internet from running in the first place.
“Given that almost anyone can launch a ransomware attack using a malicious macro, Microsoft’s indecision around disabling of macros should scare everyone,” said Kevin Bocek, vice president of security strategy and threat intelligence for Venafi. “While the company has switched course a second time on disabling macros, the fact that there was backlash from the user community suggests that macros could persist as a ripe attack vector.”
The findings, Venafi argues, are a strong argument for machine identity management control planes, which would drive specific business outcomes such as observability, consistency, and reliability. Code signing, it says, is a “key machine identity management security control” that helps eliminate macro-powered ransomware attacks.
“Using code signing certificates to authenticate macros means that any unsigned macros cannot execute, stopping ransomware attacks in its tracks,” Bocek concludes. “This is an opportunity for security teams to step up and protect their businesses, especially in banking, insurance, healthcare and energy where macros and Office documents are used every day to power decision making.”
- Get ultimate device protection with the very best antivirus (opens in new tab)
Audio player loading… New ransomware figures from Venafi and Forensic Pathways have shed some light on to why Microsoft is currently so worried about the security of Office macros. Over the course of five months (November 2021 to March 2022), the two companies analyzed 35 million dark web URLs, including…
Recent Posts
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
- Lenovo is going all out with yet another funky laptop design: this time, it’s a business notebook with a foldable OLED screen
- Elon Musk’s first month of destroying America will cost us decades
- Fortnite’s new season leans heavily on heist mechanics
- I installed iOS 18.4 dev beta and the big Siri intelligence update is nowhere to be found
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010