Cybercriminals appear to have learned a new method for bypassing anti-spam filters by sending an email with a blank Word document attached, but which contains suspicious macros , according to several security researchers.
The lure for the recipient to open the file is anything but unusual, as it is a document that pretends to contain financial information of some kind (invoice, bank statement, bill). However, it contains absolutely no information, except for malicious payload scripts in the form of macros.
The characteristic feature of macros used in Office components is to help the user perform repetitive tasks in an automated manner, by executing a series of predefined commands.
Malware developers have seen the potential of this method, and have begun to incorporate malicious commands that will trigger the download and execution of various scripts on the user's computer.
As a precaution, Microsoft has this feature disabled by default, providing the option for those who need it to enable it. Additionally, after enabling macros, a message informs the user of the associated risks.
Security researchers at Bitdefender have found a spam campaign that relies on documents with malicious macro commands to send malware, which could be ransomware.
In most cases, anti-spam filters available on the email server will prevent a malicious message from reaching the Inbox, but researchers say that in this case, because the document does not contain any text, therefore clean, the filter cannot stop it.
BitDefender says the command code can bypass antivirus programs, meaning the malicious message is capable of passing through another computer's defense system.
It appears that this spam campaign had at least 7,000 emails delivered in one day, mostly to users in Italy, France, the US, the UK, Australia, Canada and Germany.
Avoiding the risk is quite simple and consists of disabling macros. If the document is opened, a security warning will inform you of the potential risk. Canceling the pop-up will not trigger the command to download the malware.

