logo

Malicious Macros and Zone Identifier Alternate Data Stream Information Bypass

ID: 34e3c727-c3f5-51ee-b924-5cf397a65cfd

STIX ID: report--34e3c727-c3f5-51ee-b924-5cf397a65cfd

Feed Name: CloudSEK Blog

Date Published: 2022-03-27

Date Updated: 2026-04-27

...
...

This report describes how attackers bypass Microsoft’s Mark of the Web and Office Protected View to run malicious VBA macros by delivering files within ISO containers that strip the Zone.Identifier metadata on extraction. It explains Windows’ zone identification mechanism, why files pulled from non-NTFS containers lack MOTW and thus run without Protected View, and recommends mitigations including defense-in-depth, enabling Microsoft Attack Surface Reduction (ASR) rules, and avoiding execution of files from suspicious container formats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.