Emotet malware attacks have been on the rise recently and are not going to stop anytime soon. The gang behind it is very active and is constantly finding new ways to infect its victims . One of the characteristics of Emotet infections is that they are the first stage of a larger attack . Often, hacking groups exploit devices infected with Emotet to deploy other malware or even ransomware.

The “HP-Bromium Threat Insights Report, October 2020” reports a 1,200% increase in Emotet attack detections from July to September (compared to the previous quarter, where attacks were limited).
Since its appearance in 2018, Emotet has been used in many hacking campaigns. Then, it goes into a “recession” for a short period of time and then comes back. Experts believe that this will continue until 2021.
Emotet typically gains access to networks through phishing emails. Hackers make the emails look convincing and trustworthy and attach malicious documents. If users open these documents, they will (in most cases) be prompted to “enable editing.” This activates the malicious macros and infects their computers with Emotet.
The attacks and malicious attachments are tailored to the victim's location. Hackers and Vietnamese and refer to topics that may interest the victims.
Emotet started as a banking trojan, but soon began to be used for mass attacks, creating backdoors in networks that hackers can sell to other malware operators (as a gateway for their own malicious campaigns). Emotet infections are often the first stage of a ransomware attack.

The hackers behind Emotet often advertise their work on hacking forums. They provide details (size, revenue, etc.) about organizations they have breached, to attract ransomware gangs and other hacking groups
Ransomware operators are increasingly leveraging Emotet, as it gives them access to compromised systems and increases the chances of a successful attack that can yield large ransoms . Given that Emotet attacks are on the rise, ransomware gangs can target even more compromised systems and make a lot of money.
To protect against Emotet and other similar attacks, organizations should take security measures, such as inspection services emailto reduce the chances of a malicious attachment being successfully delivered. In addition, all systems should receive the latest security to patch known vulnerabilities that can be exploited by cybercriminals.
Source: ZDNet
