After almost two months, the Emotet botnet is back with a new campaign targeting 100,000 users per day.

Emotet started as a banking trojan in 2014 and has been evolving ever since, resulting in it being used for various malicious activities. It is now capable of installing various malware on victims’ machines (info-stealers, email harvesters, ransomware, etc.). It was last seen in October and previously in July. Before that, in February, it was used in a campaign that sent SMS messages purporting to come from banks.
According to Brad Haas, a researcher at Cofense, the Emotet botnet is quite prolific in sending malicious emails, but there can be weeks or even months of complete inactivity. “This year, such a gap lasted from February to mid-July, the longest break Cofense has seen in recent years. Since then, regular Emotet activity has been observed until late October, when there was another interruption.”
However, Emotet is back again. Several security firms have spotted the latest campaign. Proofpoint tweeted: “We are seeing 100k+ messages in English, German, Spanish, Italian and other languages.” According to the company, hackers are using Thread hijacking technique with malicious Word attachments, zip files and URLs.
Thread hijacking is a new technique used by Emotet, according to researchers at Palo Alto Networks. The botnet's operators jump into an existing emailby replying to a real email sent by a target. The recipient has no reason to believe that the email is malicious.
A Proofpoint researcher said: “Our team is still examining the new samples and so far we have only found minor changes. For example, the Emotet binary is now used as a DLL instead of an .exe.” “We are seeing hundreds of thousands of malicious emails per day related to Emotet.”
The researcher added that the most interesting thing about this new Emotet campaign is the timing.

“We typically see Emotet go down between December 24th and early January,” he noted. “If they continue this pattern, this recent campaign will be incredibly short-lived.”
Malwarebytes researchers have noted that hackers are using different themes to trick users into activating malicious macros. Of course, COVID-19. Researchers have also noticed that the Emotet gang loads its payload with a fake error message.
The Cofense team observed the same activity, noting that it marks an evolution for the Emotet gang.
“unaware victims that they have just been infected,” he said. “The document still contains malicious macros to install Emotet, and still claims to be a ‘protected’ document that requires users to enable macros to open it. The old version would not give any visible response after macros were enabled, which might have raised suspicions in the victim. The new version creates a dialog box that says ‘Word encountered an error while trying to open the file.’ This gives the user an explanation as to why they are not seeing the content , and is therefore more likely to ignore the whole incident while Emotet is running in the background.”
According to the researchers, some of the hijacked threads ask recipients to open a .zip attachment and provide a password.
System administrators should be on the lookout. “Many criminals see the holidays as a golden opportunity to launch new attacks, as many companies have limited staff. This year, things are more critical, due to the pandemic and the recent SolarWinds. We urge organizations to be extra vigilant and continue to take steps to secure their networks,” the researchers said.
Source: Threatpost
