The Emotet malware is targeting users again after its operators fixed a bug that allowed people to avoid infection when opening malicious attachments in phishing emails.
Phishing email attachments are the primary distribution method for the popular Emotet malware. If a user opens the attachment, malicious macros or scripts will download the Emotet DLL and load it into memory.
See also: Ransomware: FIN12 group gets much faster at encrypting networks

Once loaded, the malware will search for and steal emails for use in future spam campaigns, and may also install additional payloads on victims' devices that can lead to ransomware attacks.
Emotet malware: The bug that caused the attacks
A few days ago, malware distributors launched a new phishing campaign that included protected ZIP file attachments password-. The files contained Windows LNK (shortcut) files and were supposed to be Word documents.
When a user double-clicked the shortcut, a command was executed that searched the shortcut file for a specific string containing Visual Basic Script code, added the code found to a new VBS file, and executed that VBS file.
However, this command contained an error and thus the VBS file was not created, as explained by the Cryptolaemus research team.
See also: Google Project Zero: We're detecting more zero-day bugs than ever before
Cryptolaemus researcher Joseph Roosentold BleepingComptuer that Emotet operators stopped the above phishing campaign when they discovered that the bug was preventing users from being infected.
Unfortunately, the attackers seem to have fixed the issue and the Emotet malware has started distributing again via malicious emails containing zip files.
Email security firm Cofense told BleepingComputer that the names of the attachments in the new Emotet campaigns are:
form.zip Form.zip Electronic form.zip PO 04252022.zip Form - Apr 25, 2022.zip Payment Status.zip BANK TRANSFER COPY.zip Transaction.zip ACH form.zip ACH payment info.zipIf you receive an email with similar password -protected attachments , do not open them. Contact your network administrators or IT security personnel immediately and ask them to review the attachment to determine whether it is malicious or not.
See also: Windows 11 security: How secure is your password?

Emotet malware
The Emotet malware was first identified by security researchers in 2014. It was originally designed as a banking trojan that attempted to infiltrate a computer and steal sensitive and private information. Later versions of the software added other malicious capabilities, including the installation of additional malware.
However, an international police operation managed to “destroy” Emotet last year. Europol , the FBI, the UK’s National Crime Agency and other police agencies worked together, taking control of the malware’s infrastructure and disrupting its operations.
The good news didn’t last long, however. In November 2021, researchers saw TrickBot malware installing a loader for Emotet on infected devices. The threat actors used a method called “Operation Reacharound” to rebuild the Emotet botnet using TrickBot’s existing infrastructure. Gradually, Emotet began to re-emerge and target users in various ways.
Source: Bleeping Computer
