After a three-month hiatus, the Emotet malware has resurfaced and has been sending malicious emails since Tuesday morning, infecting devices around the world.

Emotet is one of the most well-known malware. It is distributed via emails containing malicious Microsoft Word and Excel. When users open these documents and enable macros, the Emotet DLL is downloaded and loaded into memory.
Once Emotet is loaded, it remains undetected and awaits instructions from a remote command and control server.
The malware is used to steal emails victims' and contacts for use in future campaigns. It can also download additional payloads such as Cobalt Strike or other malware that typically leads to ransomware attacks .
See also: Sharp Panda hacking group uses a variant of the “Soul” malware framework
The Emotet malware was considered the most widely distributed malware in the past. Gradually, its spread decreased, and in January 2021, authorities managed to destroy its infrastructure. The malware disappeared for a few months, but returned in November of the same year. Since then, several new campaigns have been detected, with the most recent in November 2022. That campaign lasted only two weeks.
Emotet returns in 2023
Cybersecurity firm Cofense and their Emotet monitoring group, Cryptolaemus, have warned that the Emotet botnet has resumed sending emails to unsuspecting victims.
Cryptolaemus mentioned the new campaign on Twitter.
Cofense also confirmed to BleepingComputer that the spam campaign began at 7:00 a.m. ET. However, not many emails have been sent so far.
“The first email we saw was around 7 a.m. EST. Volume remains low at this time as they continue to recreate and gather new credentials to leverage and target address books,” Cofense told BleepingComputer.
The attackers behind the new Emotet campaign are using emails that purport to be invoices.
These emails contain ZIP files with Word documents that are larger than 500 MB in size. They are designed to make them difficult to detect by security solutions .
The malicious Microsoft Word documents use 'Red Dawn' document template , prompting users to activate the document's content to view it properly.
See also: Acer data breach: Data being sold on hacking forum
These documents contain macros that will download the Emotet loader as a DLL from compromised websites.
Once downloaded, Emotet will be saved to a folder under %LocalAppData% and launched using regsvr32.exe.
Like the Word document, the Emotet DLL has also been enhanced to be 526 MB in size to prevent it from being detected as malware by antivirus software.
This evasion technique appears to be successful. A scan on VirusTotal showed that the Emotet malware was only detected by one security.
Once executed, Emotet runs in the background, waiting for commands, which will likely install further payloads on the victim’s device. As we said above, these payloads can be used to remotely access the device, which is then used to further spread across the compromised network. These attacks usually lead to data theft and ransomware attacks.
According to Cofense, this new campaign appears to simply steal data (for future attacks).

Recent Microsoft changes help protect against Emotet
While Emotet is trying to rebuild its network, the current method may not be very successful after some recent changes by Microsoft.
In July 2022, Microsoft disabled macros by default in Microsoft Office documents downloaded from the Internet. Due to this change, users who open a malicious Emotet document will receive a message stating that macros are disabled because the source of the file is not trusted.
ANALYGENCE senior vulnerability analyst Will Dormanntold BleepingComputer that this change also affects attachments saved from emails.
See also: TPM 2.0 vulnerabilities put cryptographic keys at risk!
Therefore, most users can remain protected unless they make an effort to enable macros.
Due to these changes, many cybercriminals have moved away from Word and Excel documents and are abusing other file, such as Microsoft OneNote, ISO images, and JS files. It is possible that the operators of the Emotet malware are making such a change to increase the chances of success of their attacks.
Although Emotet takes frequent breaks, its resurgence shows that it continues to pose a serious threat to users and businesses. It is important for businesses to take steps to protect themselves from this type of attack, including implementing strong security measures such as firewalls, antivirus software, email filtering solutions, etc. It is also important to educate employees about the risks posed by this type of malware, so that they know how to identify potential threats and take steps to protect themselves from them.
Source: www.bleepingcomputer.com
