Skip to main content

Office VBA + AMSI: Parting the veil on malicious macros

  • September 12, 2018
  • 6 replies
  • 19 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
September 12, 2018, By:Giulia Biagini, Microsoft Threat Intelligence Center
Sriram Iyer, Office Security
Karthik Selvaraj, Windows Defender ATP Research
 
As part of our continued efforts to tackle entire classes of threats, Office 365 client applications now integrate with Antimalware Scan Interface (AMSI), enabling antivirus and other security solutions to scan macros and other scripts at runtime to check for malicious behavior.
 
Macro-based threats have always been a prevalent entry point for malware, but we have observed a resurgence in recent years. Continuous improvements in platform and application security have led to the decline of software exploits, and attackers have found a viable alternative infection vector in social engineering attacks that abuse functionalities like VBA macros. Microsoft, along with the rest of the industry, observed attackers transition from exploits to using malicious macros to infect endpoints. Malicious macros have since showed up in commodity malware campaigns, targeted attacks, and in red-team activities.
 

Figure 1. Prevalence of the exploit vs macro attack vector observed via Windows Defender ATP telemetry
 
To counter this threat, we invested in building better detection mechanisms that expose macro behavior through runtime instrumentation within our threat protection solutions in the cloud. We’re bringing this instrumentation directly into Office 365 client applications. More importantly, we’re exposing this capability through AMSI, an open interface, making it accessible to any antivirus solution.
 
Full Article.

6 replies

10d
Popular Voice
Forum|alt.badge.img+19
  • Popular Voice
  • 103 replies
  • February 6, 2019
So does Webroot support AMSI? If not, are there plans to do so in the future?

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
@LLiddell have you any info on this query at all?
Thank you.

LLiddell
Forum|alt.badge.img+36
  • Retired Webrooter
  • 1449 replies
  • February 6, 2019
Asking the Product team, as I'm not 100% sure.

sealey
New Member
Forum|alt.badge.img+5
  • New Member
  • 32 replies
  • February 21, 2019
Hi @LLiddell did you get a response about this? Our security team is interested in any plans that Webroot may have.

JGiffard
Forum|alt.badge.img+31
  • Retired Webrooter
  • 104 replies
  • February 25, 2019
Hi there.

We will be using AMSI for a forthcoming feature. Once I'm able to share more information, I will do so.

Regards

Joanthan

Senior Product Manager
WSA Business

10d
Popular Voice
Forum|alt.badge.img+19
  • Popular Voice
  • 103 replies
  • February 26, 2019
That's great news! Hope it is soon .....

Reply