Researchers at Microsofts Malware Protection Center are warning of a new wave of attacks leveraging malicious macros using a new sneaky trick. The experts were initially deceived by the macro used by the threat actors. When the macro is executed it decrypts the string in the Caption field for CommandButton3, which turns out to be a URL. The macro will connect to the URL to download a payload which we detect as Ransom:Win32/Locky (SHA1: b91daa9b78720acb2f008048f5844d8f1649a5c4)”]
Source: http://securityaffairs.co/wordpress/47559/malware/malware-macros.html

