{"success":true,"data":{"id":"office-macro-enable-lure","label":"Office macro enable lure","description":"Email instructs recipient to open an attached Office document and enable macros, editing, or \"active content\" to view it — the canonical initial-access technique for Emotet, QakBot, and macro-based ransomware; Microsoft disabled macros by default in externally-downloaded files in 2022 (CVE mitigation), so attackers now coach victims in the email body; legitimate senders never need to ask users to lower security settings to view documents.","tier":"danger","category":"other","isThin":false}}