After a five-month hiatus, the Emotet malware operation is back and sending phishing emails to users.

Emotet malware infection occurs through phishing that include malicious Excel or Word documents. If users open these documents and enable macros, the Emotet DLL will be downloaded to the device and loaded into memory.
The malware, once loaded, will search for and steal emails to use for other spam attacks in the future. It also often installs other payloads on the victim's device that lead to ransomware (e.g. Cobalt Strike).
See also: Cryptocurrency exchange Deribit hacked
Emotet is one of the most popular malware and has been used in numerous attacks in recent years. However, as of mid-June 2022, no new infections have been detected.
Emotet is back
On November 2, researchers from the Cryptolaemus noticed a new Emotet campaign that begins, as usual, with phishing emails.
Proofpoint threat researcher and Cryptolaemus member Tommy Madjartold BleepingComputer that current Emotet campaigns use stolen email reply chains to distribute malicious Excel file attachments.
From samples found on VirusTotal, we see that malicious attachments are sent to users all over the world, with different language options and different file names. These files are usually presented as invoices, scans, online forms, or other fake documents that try to trick people into opening them.
Some examples of file names are listed below:
Scan_20220211_77219.xls fattura novembre 2022.xls BFE-011122 XNIZ-021122.xls FH-1612 report.xls 2022-11-02_1739.xls Fattura 2022 - IT 00225.xls RHU-011122 OOON-021122.xls Electronic form.xls Rechnungs-Details.xls Gmail_2022-02-11_1621.xls gescanntes-Dokument 2022.02.11_1028.xls Rechnungs-Details.xls DETALLES-0211.xls Dokumente-vom-Notar 02.11.2022.xls INVOICE0000004678.xls SCAN594_00088.xls Copia Fattura.xls Form.xls Form - 02 Nov, 2022.xls Nuovo documento 2022.11.02.xls Invoice Copies 2022-11-02_1008, USA.xls payments 2022-11-02_1011, USA.xls
Today's Emotet campaign also features a new Excel template that contains instructions for bypassing Microsoft's Protected View, making it easier for attackers to gain access to your information and compromise your computer.
Every time you download a file from the internet - whether as an email attachment or not - Microsoft will add a MoTW (Mark-of-the-Web) flag to it
Microsoft Office automatically opens documents with the MoTW flag in Protected View, which prevents macros that install malware from running.
However, the new file attachment in the Emotet campaign instructs users to bypass Microsoft Office Protected View by copying the file to the trusted “Templates” folder.
Windows will warn users that copying a file to the “Templates” folder requires “administrator” privileges. Despite this warning, most users who try to copy the file will likely end up clicking the 'Continue' button.
See also: Dropbox announces security breach – Hacker stole GitHub repositories
When you open the attached file from the 'Templates' folder, macros will be executed which will lead to the download of Emotet malware to the computer.

The Emotet malware is downloaded as a DLL to various randomly named folders in %UserProfile%\AppData\Local, like the example below.
The macros will then launch the DLL using the legitimate regsvr32.exe command.
The malware will run silently in the background after being downloaded, and will connect to a Command and Control server to receive further instructions or install another malicious payload.
According to Madjar, in the new campaign, Emotet does not install additional payloads on victims' devices.
However, in the past, Emotet used to install other malware such as TrickBot and Cobalt Strike beacons.
Ransomware gangs use Cobalt Strike beacons for initial access, and can then spread throughout the network to steal data and eventually encrypt devices.
See also: Play Store: Beware! 4 malicious Android apps found
Emotet infections have been used in the past to give the Ryuk and Conti initial access to corporate networks.
After the Conti gang's activities were disrupted in June, Emotet partnered with the BlackCat and Quantum.
Emotet malware was once considered the most widespread malware.
In early 2021, however, an international police operation, coordinated by Europol and Eurojust, took control of the Emotet infrastructure, disrupted the malware , and arrested two individuals.
German law enforcement used the infrastructure to deliver an Emotet module that uninstalled the malware from infected devices on April 25, 2021.
In November 2021, however, Emotet made a comeback. Since then, several attacks have been carried out until June 2022. As we said above, there was a pause after June, but now new phishing emails distributing Emotet have been discovered, which means we need to be very careful!
Source: www.bleepingcomputer.com
