HomeSecurityNew service checks if your email was used in a spam campaign by...

New service checks if your email was used in an Emotet spam campaign

Italian cybersecurity company TG Soft has launched a new service called “Have I Been Emotet”, which allows users to check whether a domain or email address has been used as a sender or recipient in an Emotet spam campaign.

Emotet is a malware that is spread through spam emails, which contain malicious Word or Excel documents. When a user opens these documents and the macros are enabled, the Emotet trojan on their computer.

Emotet malware

After infecting the victim's computer, Emotet steals the email and transfers it to servers under the attacker's control. This email will be used in future spam campaigns, allowing the malicious actor to make the malicious spam appear legitimate in order to attract more victims.

Over time, the Emotet trojan downloads and installs other malware, such as TrickBot and QakBot, on a victim's computer. These trojans lead to ransomware attacks carried out by the operators of Ryuk, Conti, and ProLock.

spam campaign

TG Soft told BleepingComputer that their database consists of monitored outbound emails generated by Emotet between August and September 23, 2020. During this period, they collected over 2.1 million email addresses from approximately 700,000 outbound emails.

To use the new service, someone can enter a domain or email address and will receive an update on how many times it was used as a sender or recipient in an Emotet spam campaign.

The “Have I Be Emotet” service provides users with the following information:

  • Real sender: Indicates that the computer using this email account has been compromised and used to send spam emails.
  • Fake sender: Indicates that your email has been stolen and used in spam campaigns.
  • Recipient: Indicates that you were a recipient of an Emotet spam email.

If a company has been affected by a cyberattack, one can check whether it has been targeted by Emotet spam campaigns, which lead to a ransomware attack. For example, Ryuk ransomware recently attacked leading healthcare provider Universal Health Services (UHS). Using this service, we can see that UHS’s domain, uhsinc.com, was used in recent Emotet campaigns and that the company received Emotet spam nine times.

new service-email-spam campaign Emotet

If someone uses this service and finds that their email address or domain has been used as a recipient, it does not necessarily mean that you are infected. To become infected, a user would have to open the email attachments and enable macros before the malware was installed. Additionally, if a user's domain has users listed as the "real" sender, then it is likely that one of the users of their email domain has been infected and their computers should be thoroughly investigated.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS