
Cyber criminals adapt to MS macro-blocking
Microsoft's decision to block internet-sourced macros by default last year is forcing attackers to find new and creative ways to compromise systems and deliver malware, according to threat researchers at Proofpoint. Financially motivated threat actors that gain initial access via email are no longer using static, predictable attack chains, but rather dynamic, rapidly changing techniques. Instead, miscreants are now finding fresh avenues for gaining initial access into victims' systems, including LNK files, ISO and RAR attachments, and Excel XLL add-ins, at least until Microsoft blocked those earlier this year.