As it turns out, Emotet is back with a new large-scale campaign that has targeted the Lithuanian National Public Health Center (NVSC), several municipalities , and state institutions.

“When recipients opened infected messages, the virus entered the institutions’ internal networks,” NVSC officials said.
“Infected computers, after downloading additional files, began sending fake emails or being used for other types of malicious activity.“.
Emotet has spread to such an extent that Lithuanian government officials, ministry representatives, and expert epidemiologists, who had previously contacted NVSC specialists via email, have also been infected after receiving malicious emails from infected systems.
The National Public Health Center of Lithuania took its systems offline to stop the further spread of Emotet.
The Center's IT staff is working with experts from the State Telecommunications Center and the National Cybersecurity Center to "clean" systems infected by Emotet and restore access to emails.

The emails were sent as replies to previous conversations
Rytis Rainys, Director of the National Cyber Security Center of Lithuania (NKSC), warned that the malicious emails were sent as replies to previous conversations and delivered the malicious code using protected files password- as attachments. The password was given in the text of the email.
This prevented anti-malware software from detecting the malicious emails, and so many people from the National Center for Public Health of Lithuania and other institutions were lured into opening the attached files, infecting their systems.
Emotet often uses the tactic of replying to previous conversations to make emails appear more credible and less distracting , thereby increasing the chances of successful infection.
This is the second major Emotet campaign to target Lithuania this year. The first was detected by NKSC in October.

Dynamic return of Emotet
After a hiatus, the Emotet botnet resurfaced on December 21st according to Microsoft, which detected a new campaign.
"The new Emotet campaign continues to use documents containing malicious macros that, when activated, link to seven malicious domains to download the Emotet payload," Microsoft said.
Source: Bleeping Computer
