Security News > 2021 > March > Microsoft Office 365 gets protection against malicious XLM macros

Microsoft has added XLM macro protection for Microsoft 365 customers by expanding the runtime defense provided by Office 365's integration with Antimalware Scan Interface to include Excel 4.0 macro scanning.
Microsoft first extended support for its Antimalware Scan Interface to Office 365 client applications in 2018 to defend customers against attacks using VBA macros.
Since AMSI started allowing Office 365 apps to block malicious VBA macros, attackers such as the ones behind Trickbot, Zloader, and Ursnif have migrated to using XLM-based malware to evade static analysis and infect their targets with malware.
With this latest improvement to Office 365, antivirus solutions like Microsoft Defender Antivirus can detect malicious XLM macros and stop malware using them in its tracks.
"Administrators can now use the existing Microsoft 365 applications policy control to configure when both XLM and VBA macros are scanned at runtime via AMSI.".
Admins can download the latest group policy template files for Microsoft 365 Apps from the Microsoft 365 download center.
News URL
Related news
- Fake Microsoft Office add-in tools push malware via SourceForge (source)
- Microsoft launches ad-supported Office apps for Windows users (source)
- Microsoft tests ad-supported Office apps for Windows users (source)
- Microsoft: New Windows scheduled task will launch Office apps faster (source)
- Microsoft releases emergency update to fix Office 2016 crashes (source)