HomeSecurityEmotet: Reuses Cobalt Strike for faster attacks

Emotet: Reuses Cobalt Strike for Faster Attacks

Just before the holidays, the notorious Emotet malware is once again directly installing Cobalt Strike beacons for quick attacks.

Emotet

See also: Emotet installs Cobalt Strike on devices allowing for faster ransomware infection

For those who don't know, Emotet is considered one of the most widespread malware infections and is distributed via phishing emails that include malicious attachments.

Once a device is infected, Emotet steals a victim's email to use in future campaigns and will then drop malware payloads, such as TrickBot and Qbot.

However, earlier this month, Emotet began testing installing Cobalt Strike Beacons on infected devices instead of their normal payloads.

Cobalt Strike is a legitimate penetration tool commonly used by malicious actors to spread laterally through an organization and ultimately deploy ransomware across a network.

Emotet continues to use Cobalt Strike

Last week, the Emotet malicious actors suspended their phishing campaigns, and researchers have not seen any further activity from the group since then.

See also: Emotet spreads via fake Adobe Windows App Installer packages

"The spam stopped last week and since then it's been quiet and nothing has happened to date," said Joseph Roosen of the Cryptolaemus Emotet group.

Cobalt Strike

However, Cryptolaemus is now warning that they have recently started installing Cobalt Strike again on devices already infected with Emotet.

According to Roosen, Emotet now downloads Cobalt Strike modules directly from its command and control server and then executes them on the infected device.

With Cobalt Strike Beacons installed directly by Emotet, malicious actors using them to spread laterally through a network can steal files and deploy malware by having direct access to compromised networks.

In a sample of Cobalt Strike, the malware will communicate with the attacker's command and control servers via a fake "jquery-3.3.1.min.js" file.

Each time the malware communicates with the C2, it will attempt to download the jQuery file, which will change a variable with new instructions each time.

See also: Anubis malware: Targets customers of 394 financial institutions

Since most of the file is legitimate jQuery source code and only some content has been changed, it blends in with legitimate traffic and makes it easy to bypass security software.

The rapid deployment of Cobalt Strike via Emotet is a significant development that should be on the radar of all Windows and network administrators and security professionals. With this increased distribution of beacons to already infected devices, it is expected that we will see an increase in corporate breaches and ultimately ransomware attacks right before or during the holidays.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS