Business Documents as Ransomware Attack Vector: How Can Organizations Protect Themselves?
On December 8, 2025, AhnLab announced the integration of Contents Disarm & Reconstruction (CDR) technology into its advanced threat response solution, AhnLab MDS. With this update, AhnLab is expanding its defense perimeter against document-based attacks arriving via email and the web.
Recently, attackers have grown increasingly sophisticated, using email attachments and business documents to distribute malware. They often use files that are nearly indistinguishable from legitimate ones to bypass security detection or exploit situations where employees have no choice but to open files for work. To address these evolving threats, AhnLab has implemented CDR in its MDS solution to bridge the response gap that can occur after the initial detection phase.

A New Standard in Defending Against Document-Based Attacks
The CDR capability in AhnLab MDS sets a new standard for document security by neutralizing potential threats embedded in documents and reconstructing them into safe, functional files that mirror the original content. This allows organizations to securely use files that traditional signature-based or behavioral analysis might miss, ensuring uninterrupted business continuity.
The feature supports a wide range of file formats—including Office, PDF, HWP, and ZIP—and fundamentally blocks threats by stripping away malicious active contents(JavaScript, Flash, and ActiveX, etc.).
Consequently, users can overcome the dilemma of blocked access and work immediately with sanitized, risk-free documents.
Automated CDR Sanitization in MDS and MTA Environments
With the addition of CDR, AhnLab MDS extends its document security capabilities beyond mere detection to proactive response.
In both MDS and MTA environments, administrators can select uploaded files or detected samples to apply CDR processing, and then download the reconstructed, safe files. Furthermore, in AhnLab MTA, the CDR capability integrates with automated response policies. This allows suspicious or malicious email attachments to be automatically sanitized and delivered to recipients without manual intervention.
This automation enables security teams to proactively neutralize document-based threats while minimizing operational overhead.
Detailed CDR processing results, logs, and reports are available through the management console, significantly enhancing security visibility and management efficiency.

Figure 1. Enhanced visibility through CDR processing logs and detailed reports
Strengthening Document Security While Improving User Experience
The CDR capability delivers 3 key benefits simultaneously:
- Enhanced document security
- Minimized business disruptions caused by false positives or missed detections
- Improved user experience
Most notably, it resolves the long-standing dilemma of “documents that must be opened for work but cannot be trusted for security,” achieving a perfect balance between robust security and productivity.
Through the adoption of CDR, AhnLab aims to proactively respond to the rising trend of document-based attacks and increasingly sophisticated threat techniques, delivering tangible and actionable security value to its customers’ environments.
Licensing and Support Scope
The CDR capability is available via the AhnLab MDS CDR Lite License. It can be activated on MDS and MTA appliances upon purchasing a separate license.
- Supported firmware: MDS 2.1.25 or higher
- Supported models: MDS 5000B / 10000B / 20000B
Existing MDS or MTA customers can easily extend their current deployments to include CDR by purchasing an additional license, without affecting existing functionalities. Licenses are managed on an annual, per-appliance basis.
AhnLab is also exploring plans to introduce an API-based “CDR Advanced” license in the future.
Lee Yeon-joo, Product Manager for AhnLab MDS, stated:
"CDR provides a practical and effective solution for document-based attacks that are difficult to address with traditional detection technologies alone. By integrating CDR (powered by the Jiransecurity SDK) into AhnLab MDS, we will continue to build a comprehensive document security framework that encompasses detection, sanitization, and secure delivery."
