At least 22 percent of reported campaigns in April 2019 delivered malware via booby-trapped macros, IBM says. Malicious macros are most often used as a dropper for a payload that serves the attackers ultimate goal. A document or spreadsheet containing malicious macros is distributed as an attachment in a phishing email or via a download link in an email. When the user opens the document, there is often some decoy content and a request to enable macros. Since then, usage has continued with a wide variety of attacks by phishers, cybercriminals and nation-state adversaries alike.”]
Source: https://securityintelligence.com/posts/how-to-fight-back-against-macro-malware/

