Malicious Office Macro Enabled by User
User enabled macros in a Word document received via email claiming to be an invoice from a vendor. Macro executed PowerShell to download and run a payload from hxxps://cdn-updates.net/update.exe. The executable was immediately flagged by behavioral analysis as exhibiting ransomware-like encryption behavior against user documents.


