Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a malicious macro?

A malicious macro is document-embedded automation used to perform an unauthorised action, commonly to launch commands or retrieve another payload. Receiving or opening the document is not the same as running the macro.

Whether code executes can depend on the file format, application version, security policy, protected-view settings and a user's response to warnings. A document may be delivered, previewed by a service, opened by the recipient and still never execute its embedded code.

Separate the stages

A useful reconstruction distinguishes:

  1. Delivery - how the document reached the device or account.
  2. Opening - which application or service accessed it.
  3. Enablement - whether active content was permitted automatically or by a user.
  4. Execution - what macro entry point or embedded instruction ran.
  5. Effect - which processes, files, connections or account actions followed.

This avoids overstating a mail attachment or recent-file record. Preview panes, malware scanners and automated content services can open a document without reproducing the user's actions or executing the macro.

Evidence that connects code to effect

Preserve the original document and its delivery context where possible. The file's hash, metadata, embedded macro code and security markings help establish what was available to run. Application logs, user-interface warnings, process creation and command-line records may then show whether execution occurred.

A macro that launches a command interpreter should be traced into its child processes, downloaded material, network connections and resulting changes. Code analysis can explain capability, but capability alone does not prove that the code ran on the device in question.

The human inference also needs care. A user may have enabled content after deception, while policy or trusted-location settings may have allowed execution without a fresh click. Conversely, the account associated with the document may not identify the person at the keyboard.

Key takeaway

Treat delivery, opening, enablement, execution and effect as separate propositions; prove each required stage from the document, application and system records rather than assuming that an attachment ran.

Reference: CIM-074Cyber Incidents & Offender Methods