schwieb
About
- Username
- schwieb
- Joined
- Visits
- 3
- Last Active
- Roles
- member
- Points
- 1
- Badges
- 0
- Posts
- 5
Reactions
-
Microsoft Word macro malware automatically adapts attack techniques for macOS, Windows
The macro in question requires binding to the OS API "system()" in order to run the external python script. Mac Office 2016 version 15.31 (released in February 2017) and later block VB from binding to that API, thus preventing macros using this particular attack vector from running. The macro will fail with a compile-time error and will not run. Version 15.32 (released in March 2017) provides user preferences to disable all VB macros from running, and version 15.33 (to be released in April) will provide IT administrators the ability to enforce this setting on all Macs under their control.
Schwieb
Principal Software Engineer
Office for Apple Platforms
Microsoft Corporation