Malicious Macros and Zone Identifier Alternate Data Stream Information Bypass
ID: 34e3c727-c3f5-51ee-b924-5cf397a65cfd
STIX ID: report--34e3c727-c3f5-51ee-b924-5cf397a65cfd
Feed Name: CloudSEK Blog
This report describes how attackers bypass Microsoft’s Mark of the Web and Office Protected View to run malicious VBA macros by delivering files within ISO containers that strip the Zone.Identifier metadata on extraction. It explains Windows’ zone identification mechanism, why files pulled from non-NTFS containers lack MOTW and thus run without Protected View, and recommends mitigations including defense-in-depth, enabling Microsoft Attack Surface Reduction (ASR) rules, and avoiding execution of files from suspicious container formats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
