← MALWARE HISTORY LAB

HISTORICAL ARCHIVE · CHAPTER 04 / 09

Macro Viruses

1990S · PROGRAMMABLE DOCUMENTS

A safe, curator-led account of a technical transition in malware history. All illustrations are conceptual and inert.

ERA / DATE RANGE1990s · Programmable documents
REPRESENTATIVE EXAMPLESMelissa · Office macros
ARCHIVE STATUSHISTORICAL CONTENT: OPEN

What changed?

Office documents became programmable through macros—useful automation features that also created a new security boundary. A document could now contain behavior, not only text and layout.

How it spread / worked conceptually

A document could carry macro behavior into a template or another document state; sharing that document could then pass the risk to a new user. No macro code is presented here.

Why it mattered

The era changed the human model of risk: opening a document could trigger behavior, even when the visitor did not think of a document as a program.

SAFE CONCEPTUAL DIAGRAM NO LIVE ACTIVITY
DOCUMENT ↓ MACRO EXECUTION ↓ TEMPLATE / DOCUMENT STATE ↓ SHARED DOCUMENT ↓ NEW USER

Representative historical examples

Melissa (1999) is a representative macro-virus incident, illustrating how document automation and email distribution could combine.

What defenders learned

Defenders strengthened macro warnings, document policies, attachment filtering, and user education.

What changed next?

Once computers became permanently networked, malware no longer needed a floppy or even necessarily a document.