In the first months of 2025, identified Barracuda's Managed Extended Detection and Response (XDR) platform a sharp increase in cyberthreats that exploited malicious macros. The number of attacks using this method against XDR customers increased by over 400 percent compared to previous months.
Malicious macros are a well-known attack method that continues to be an effective way for cybercriminals to gain entry into corporate IT environments.
“Malicious macros are often spread via email attachments that appear to contain important documents, such as invoices or receipts. When a user activates the macros, it often leads to malicious code being downloaded and executed. This then facilitates everything from data theft to ransomware attacks,” says Klas Palmer, Security expert at Barracuda Networks.
Why are malicious macros a threat?
Macros are embedded commands (“scripts”) in documents that are used to automate tasks and streamline work processes, for example. But when cybercriminals exploits the same technology, it is instead about installing malicious code, stealing sensitive information and creating backdoors in the systems.
The threat is particularly serious because many companies still use legacy IT systems that lack modern security features. In addition, employees may unknowingly click on attachments and enable macros, especially if they receive emails that appear urgent or important.

How to protect your business
To minimize the risk of being affected by malicious macros, you should:
- Disable macros where possible in Microsoft Office applications.
- Educate employees about the risks of opening unknown attachments and enabling macros.
- Update IT systems regularly with the latest security patches.
- Use advanced security solutions to detect and block malicious macros.
– Companies must always be proactive in their cybersecurity and do not underestimate the threat from malicious macros. By combining protective technology with employee training, the risk of attacks can be significantly reduced, concludes Klas Palmer.








