
The Emotet malware has reappeared, with a new malicious email attachment that appearsto be created by Windows 10 Mobile, an operating system that Microsoft stopped supporting in January 2020.
The Emotet botnet spreads via spam emails, which contain malicious Word documents. These Word documents contain malicious macros, which if activated, will download and install Emotet on the computer .
Once installed, Emotet will steal the victim's email to use in other spam campaigns. In addition, it will download and install other malware, such as TrickBot and QBot , which usually lead to ransomware attacks .
Tricking users into enabling malicious Word macros
When the user opens a Word document with macros, Microsoft Word will open it in “Protected View”, which does not allow the macros to run.
For this reason, Emotet malware administrators create Word documents designed to trick the user into clicking the “Enable Editing” and “Enable Content” buttons, which will enable malicious macros.
A recent review of Emotet's malicious Word documents, by the monitoring group Cryptolaemus, showed that a new document template that appears to be created on "Windows 10 Mobile."
The notification that users see says the following:
Windows 10 Mobile
The operation did not complete successfully because the file was created on a Windows 10 Mobile device. To view and edit the document, tap “Enable Editing, and then click “Enable Content.”

The Windows 10 Mobile operating system was first released in 2015, but due to its small market share, Microsoft stopped supporting it in January 2020.
While there are people who continue to use Windows 10 Mobile, their number is very small and the chances of someone sending you documents from a Windows 10 Mobile are relatively low. Therefore, you should be very careful, as it is almost impossible to receive such an email that is not malicious. If you receive an email with a Word document stating that it was created on Windows 10 Mobile, do not activate editing or the content. Discard it immediately!
