Once the malicious VBA code is executed, the AutoOpen() function is automatically called. Asks victim to enable Macro security option When the Word file is opened, it shows notifies victims to enable the Macro security option, which allows the malicious VBA code to be executed. We then analyzed the sample, and in this blog we are going to explain how it works, step by step.
The sample targeted both Apple Mac OS X and Microsoft Windows systems. On March 16, FortiGuard Labs captured a new Word file that spreads malware by executing malicious VBA (Visual Basic for Applications) code.