HomeSecurityEmotet: New campaigns masquerade as Windows Update emails

Emotet: New campaigns masquerade as Windows Update emails

In today's cybersecurity landscape, the Emotet botnet is one of the largest sources of malspam – a term used to describe emails that deliver malicious software attachments.

These malspam campaigns are absolutely vital to Emotet operators.

It is the base that supports the botnet, feeding new victims to the engine called Emotet – a Malware-as-a-Service (MaaS) operation that is rented out to other criminal groups.

emote

To avoid having their emails picked up and marked as "malicious" or "spam," the Emotet group regularly changes the way these messages are delivered and how attached files.

Emotet operators change email subjects, email text, the type of attached files, and even the content of the attached file, which is just as important as the rest of the email.

This is because users who receive Emotet malspam, in addition to reading the email and opening the file, must allow the file to run automated scripts called “macros.” Office macros are executed after the user clicks the “Enable Editing” button that appears within an Office.

Tricking users into enabling processing is just as important to malware operators as designing their email templates, their malware, or the botnet's backend infrastructure

Over the years, Emotet has developed a collection of Office documents that use a wide variety of “attractions” to convince users to click the “Enable Editing” button.

But this week, Emotet returned with a new lure of documents.

Attachments sent in recent Emotet campaigns show a message claiming to be from Windows Update, telling users that their Office application needs to be updated. Of course, this must be done by clicking the Enable Editing button.

According to an update from the Cryptolaemus team, these Emotet lures have been spamming users located all over the world.

According to this report, on some infected hosts, Emotet installed the TrickBot trojan, confirming a ZDNet report released earlier this week that the TrickBot botnet survived a recent takedown attempt by Microsoft and its partners.

These trapped documents are sent from emails with fake identities, appearing to come from acquaintances and business partners.

Additionally, Emotet often uses a technique called "conversation hijacking," through which it steals email threads from infected hosts, inserts itself into the thread with a reply impersonating one of the participants, and adds attached Office documents.

The technique is difficult to detect, especially among users who work with business emails on a daily basis, which is why Emotet very often manages to infect corporate or government networks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS