Don't open emails with Christmas cards because you'll get hacked: Hackers are aiming to kill the Christmas spirit by hiding malware in phishing emails that invite you to parties.
Research by security firm Cofense has revealed that hackers behind the dangerous Emotet botnet are using holiday-themed phishing emails to trick their victims.

The company warns that this tactic is being used to lure employees who are excited about the holidays with fake emails about Christmas parties.
Cofense discovered phishing emails with titles like “Christmas party next week” that, while seemingly innocent, contained a macro- enabled Microsoft Word attachment disguised as menu options for a holiday meal. The emails are crafted in such a way that it is difficult to discern their malicious nature.
Asking the user to “enable editing” to see the menu, clicking on the attachment will execute the embedded macros and install the Emotet malware, which could lead to more ransomware downloads, more spam and phishing emails
Cofense says that despite its seductive appearance, it can be detected due to the use of an old Microsoft Word .doc format, as well as a default text selection that is not reminiscent of your company's style.

However, these emails still pose very valid threats to businesses of all sizes and remind us of the need for employee awareness of cybersecurity.
“If your phishing protection program is aligned with the active threats facing organizations, then this is exactly the model you should use to train your users to identify real phishing emails,” writes Tonia Dudley of Cofense Security Solutions.
Recent data from Malwarebytes shows a 37% increase in attacks using Emotet.
