Macro-enabled document delivered inside archive to bypass filters
Attackers routinely wrap macro-enabled documents in archives because many email and download filters scan attachments by extension without recursing into containers. A macro-laden .docm stowed inside a plain ZIP can arrive at the user intact; opening it and enabling macros then runs embedded code in the Office security context. This wrapper trick is a reliable delivery path for phishing and initial access. In this demo a benign macro document is archived to illustrate the same maneuver: the embedded macro only opens Calculator, keeping analysis safe. The Archive Engine recurses into the ZIP, extracts the inner document, and passes it to macro analysis before anything reaches the desktop. The unwrapped threat is neutralized at the gateway, not on the user's machine.
Attack Technique
Archive-wrapped macro document
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗