HomeSecurityEmotet botnet: Punisher hacker replaces malicious payloads with GIFs

Emotet botnet: Punisher hacker replaces malicious payloads with GIFs

Emotet botnet Hacker-punisher GIFs

An unknown hacker-punisher is sabotaging the recently revamped Emotet botnet, replacing Emotet payloads with animated GIFs and protecting victims from infection.

The sabotage began on July 21st and has evolved from a simple joke to a serious issue affecting much of the Emotet operation.

What's really going on with the Emotet botnet and how did the hacker-punisher target it?

The Emotet botnet operates through spam emails, which supposedly contain business-related messages. These emails contain either a malicious Office document or a link to a malicious file , which users are asked to download to their computer.

When users open one of these files and click links within the file or enable the “Enable editing” feature to allow macros (automated scripts) to run, the automated scripts download the Emotet malware and its various components from the Internet.

By “Internet” we actually mean “ compromised WordPress websites ”, where the Emotet gang temporarily stores its malware components , or malicious payloads

These temporary hosting locations are also the Achilles heel of the Emotet botnet.

The Emotet gang controls these compromised websites via web shells, a type of malware installed on compromised servers to allow attackers to manipulate the server.

But the Emotet gang doesn't use the best web shells available on the market. It mostly uses open-source scripts and has the same password for all its web shells, leaving its infrastructure vulnerable to easy compromise if someone guesses the web shell password. This weakness was also exploited by the hacker-punisher.

Punisher hacker sabotages Emotet botnet

Emotet, considered the most dangerous malware , had been dormant for more than five months, but resurfaced last week.

However, a hacker-punisher seems to have discovered the common password of web shells and decided to sabotage Emotet's return.

The unknown attacker replaces the Emotet payloads on some of the compromised WordPress sites with animated GIFs. This means that when victims open the malicious Office files, they are not infected as Emotet is not downloaded and executed on their systems.

In recent days, the attacker has replaced Emotet payloads with several popular GIFs.

The first, spotted on Tuesday, is this Blink 182 “WTF” GIF.

On the second day, the James Franco GIF was used.

After that, we had the Hackerman GIF.

GIFs are usually obtained from either Imgur or Giphy, two GIF-hosting services.

Emotet botnet: Large portion of malicious enterprise affected

Approximately a quarter of all daily Emotet payload links are replaced with GIFs, causing serious losses to the Emotet gang.

The Emotet gang is aware of what's going on and apparently shut down the botnet on Thursday in an effort to remove the attacker from its web shell network.

In some cases, hackers managed to replace the GIF with the malicious payload again.

The hacker-punisher managed to cause serious damage to Emotet last week.

Security researchers believe that the Emotet gang is still trying to gain control of its web shells.

The identity of the hackerunknown -punisher is currently . Some theories suggest it is a rival malware gang or a member of the cybersecurity industry.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS