A shift often shows up as fewer macro-enabled Office documents and more emails linking to ISO, RAR, ZIP, or similar container files. Defenders may also see helper scripts, PowerShell activity, MSHTA use, and downloaded batch or VBS files after a link is clicked. A consistent lure theme with changing file types is a strong signal that the actor has adapted delivery methods.
What the shift from macro documents to URLs and container files looks like
The most useful clue is a delivery pattern change, not a single file type. When an actor stops relying on macro-enabled Office documents and starts pushing recipients toward links and archives, the campaign is usually adapting to macro blocking, attachment filtering, or user suspicion. The lure often stays consistent while the delivery wrapper changes, which helps defenders separate a new payload path from a new campaign.
That shift usually means the initial access method has moved earlier in the chain. Instead of embedding active code in the document itself, the attacker uses the email to drive the user to an external download or a container file, where the next-stage payload can be unpacked or executed outside mail gateway scrutiny.
Watch for a decline in macro-laden Word or Excel files and a rise in ISO, RAR, ZIP, and similar containers, especially when the message body contains a short URL or a prompt to open a hosted file. The container is often just a staging wrapper; what matters is whether the campaign consistently uses it to deliver scripts, launchers, or secondary payloads after the click.
What usually appears after the click
Once the user follows the link or mounts the archive, defenders often see helper components rather than a traditional office macro chain. Common follow-on activity includes PowerShell, MSHTA, batch files, VBS, or other script interpreters that retrieve or unpack the real payload. That is a strong sign the actor is preserving the same objective while swapping the initial loader.
In practice, this means the compromise path has become more modular. The email no longer needs to carry executable logic directly, because the link or container file becomes the transport layer and the script becomes the execution layer. This can reduce the visibility of the first stage while increasing the importance of endpoint telemetry after the user action.
It is also common to see the same lure theme reused across many messages, even as the attachment type changes. If the subject line, branding, or urgency pattern stays stable while the file format shifts, that consistency is often more meaningful than any one attachment hash.
How defenders should interpret the pattern change
A move from macros to URLs and container files usually signals adaptation to controls rather than a random variation. The actor is testing which stage is easier to get through, such as mail filtering, attachment sandboxing, or user behavior defenses. That makes the transition itself an intelligence point: it can reveal that the campaign operator has learned which delivery paths are more durable.
Look for the combination of a familiar lure, changed attachment format, and post-click script execution. When those elements line up, you are not just seeing phishing, you are seeing a delivery chain that has been re-engineered to keep the same social-engineering objective with a different technical wrapper.
For container-based delivery and archive handling, NIST SP 800-190 Container Security is useful background on how packaged content, image trust, and runtime exposure can create hidden risk. For the execution side of the pattern, MITRE ATT&CK Enterprise Matrix helps map the helper-script and launcher activity to adversary technique.
Risk and Threat Considerations
This shift matters because link-based delivery and container files can bypass controls that were tuned to catch obvious macro malware. The main risk is that defenders may misread the lower macro volume as a decline in activity, when the attacker has simply moved execution into a later stage that is harder to see in email alone.
Failure mechanism: The user clicks a link or opens a container, then a script, downloader, or native interpreter launches the payload with a trusted user context. That breaks the assumption that blocking Office macros materially contains the campaign.
Impact: The campaign can continue with a lower-friction delivery path, broader endpoint exposure, and less reliable email-only detection, which increases the chance that the next stage executes before containment starts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1059 — Command and Scripting Interpreter | Helper scripts, PowerShell and MSHTA are common execution stages after phishing delivery. |
| T1204 — User Execution | URL clicks and opening container files depend on user-triggered execution. | |
| T1566 — Phishing | The question is about phishing delivery changes and campaign adaptation. | |
| Recommendation — Map post-click script activity to T1059 and hunt for unusual script launch patterns. Correlate user click events with subsequent payload execution to detect T1204. Track phishing delivery variants and update detections for attachment and URL-based lures. | ||
| NIST SP 800-53 Rev 5 | SI-4 — System Monitoring | Email-to-endpoint transitions require monitoring of scripts and suspicious launches. |
| AU-6 — Audit Review, Analysis, and Reporting | Campaign shifts are best confirmed by reviewing correlated email and endpoint events. | |
| Recommendation — Monitor endpoint and email telemetry together to spot post-click execution chains. Review correlated audit data to confirm a delivery-method shift. | ||
Practitioner Guidance
What to verify: Treat the delivery shift as a hunting lead and confirm whether the same sender infrastructure, lure wording, and redirect chain recur across messages. If the campaign identity is stable but the attachment type changes, prioritize timeline correlation over individual file analysis.
What to measure: Track the ratio of macro-enabled attachments to URL-delivered and archive-delivered lures, then compare that trend with downstream PowerShell, MSHTA, and script execution on endpoints. A falling macro count with stable lure volume often means the actor has changed tactics, not reduced activity.
Practitioner takeaway: The important signal is not that macros disappeared, it is that the attacker preserved the lure and moved execution into a less obvious stage, so detection should follow the delivery chain rather than the file format alone.
Related resources from NHI Mgmt Group
- What are the signs that a phishing campaign is using DLL sideloading to deliver malware?
- What are the signs that a malicious XLL campaign is using decoy documents and staged loaders?
- What are the signs that an AiTM phishing campaign is operating inside a legitimate-looking login flow?
- What are the signs that a phishing campaign is using an attacker-in-the-middle kit to steal session access?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org