Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Word macro virus is a virus that uses Word macro code to infect documents or templates and spread to other Word files. Its code may run when an infected file is opened with macros enabled, but opening a macro-enabled document does not automatically mean its macros will run.

What makes a Word macro a virus?

A macro is code that can automate tasks in Word. It becomes a macro virus when it is malicious and spreads by infecting other files, such as Word documents or templates. Depending on its design, it may copy itself into additional files when Word documents are opened or closed.

That spreading behavior is the key distinction: a harmful macro that performs an unwanted action but does not infect other files is macro malware, but it is not necessarily a virus. Microsoft describes macro viruses as malware that spreads through infected documents and runs when a document is opened. Microsoft Learn’s malware classification explains this distinction.

What can a Word macro virus do?

Its effects depend on the code. A virus may propagate by changing documents or templates, and it may also alter Word’s security behavior or affect document contents. Historical examples show that the risks were not limited to copying itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Historical example: Concept.A

Microsoft describes Virus:WM/Concept.A as the first widely known Word macro virus, written for Word 6. It spread by infecting documents and templates, including Word’s Normal template. This is a historical example, not evidence that the strain is currently active. Microsoft Security Intelligence’s Concept.A entry provides its description.

Historical example: DocCopy.L

Microsoft’s entry for Virus:W97M/DocCopy.L says it infected Word’s global template and documents opened or closed in Word. It could also disable macro warnings and remove password protection from documents, leaving them open to infection. The entry was published July 29, 2011, and updated September 15, 2017; it documents historical behavior rather than present-day prevalence. Microsoft Security Intelligence’s DocCopy.L entry gives the details.

Does a .docm file mean a document is infected?

No. The extension identifies the file format, not whether the file is malicious. A modern Word document with embedded macros uses .docm; a standard modern Word document uses .docx. A .docm file can contain legitimate macros, but because it can hold active content, treat it cautiously if you do not know its source or purpose. Microsoft’s current guidance also identifies macro-enabled formats such as Excel .xlsm and PowerPoint .pptm. Microsoft Support’s macro-virus guidance covers these formats and the Office versions to which its advice applies.

Will Word run macros when you open a file?

Not necessarily. Microsoft says Microsoft 365 does not run active content automatically unless the document is trusted or opened from a trusted location. A malicious macro may run if a user enables its content. Viewing a file or making simple edits usually does not require running its macros.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not enable macros just because a document appears to come from someone familiar. Microsoft’s instruction is: “Do not select Enable Content unless you’re certain that you know exactly what that active content does, even if the file appears to come from a person or organization that you trust.” If you are unsure what a macro does, leave the content disabled.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you reduce the risk?

  • Keep macros disabled for files whose macros you do not need or understand.
  • Do not select Enable Content based only on the sender’s name or the document’s appearance.
  • Use current anti-malware software. Microsoft says modern anti-malware software should detect and block known macro viruses; that is not a guarantee against every unknown or modified threat.
  • If you need a document’s contents but not its automation, view or edit it without enabling active content where possible.

These protections reduce risk, but the extension alone cannot establish whether a file is safe: assess its source and whether its macros are expected before allowing them to run.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.