Emotet reestablishes itself at the top of the malware world
- Reference: 1650535325
- News link: https://www.theregister.co.uk/2022/04/21/emotet-resurgence-email/
- Source link:
In a [1]March threat index , Check Point researchers put the Windows software nasty at the top of its list as the most widely deployed malware, menacing or infecting as much as 10 percent of organizations around the globe during the month – a seemingly unbelievable estimate, and apparently double that of February.
Now Kaspersky Labs says a rapidly accelerating and complex spam email campaign is enticing marks with fraudulent messages designed to trick one into unpacking and installing Emotet or Qbot malware that can steal information, collect data on a compromised corporate network, and move laterally through the network and install ransomware or other trojans on networked devices.
[2]
Qbot, which is linked to the operators of Emotet, can also access and steal emails, Andrey Kovtun, email threats protection group manager for Kaspersky, wrote in a [3]blog post this week.
[4]
[5]
The Kaspersky team said it had picked up 3,000 malicious Emotet-linked emails in February, and about 30,000 in a month later, written in such languages as English, French, Italian, Polish, Russian and Spanish.
"Some letters that cybercriminals send to the recipients contain a malicious attachment," Kovtun wrote. "In other cases, it has a link which leads to a file placed in a legitimate popular cloud-hosting service. Often, malware is contained in an encrypted archive, with the password mentioned in the e-mail body."
[6]
To increase the chances that the email recipient will open the attachment or download the malicious file through the link, the spam email often says that it contains important information, such as a commercial offer.
"Our experts have concluded that these e-mails are being distributed as part of a coordinated campaign that aims to spread banking Trojans," he wrote.
Can't keep profitable malware down
As an indication of the continuing development of Emotet by its operators, Cryptolaemus, the group of security researchers and systems administrators that came together more than two years ago to fight back against Emotet, [7]said on Twitter this week that one of the botnet subgroups has switched from 32-bit to 64-bit for loaders and stealer modules.
The reemergence of Emotet into the top levels of the malware world happened quickly. In February 2021, Europol and police forces from such places as the US, Germany, the UK and Ukraine conducted a [8]multinational takedown of the main botnet deploying Emotet. The operation included raids of the homes in Ukraine of the alleged operators.
Europol in a statement at the time said the raid severely disrupted Emotet's operations, which was used to "infiltrate thousands of companies and millions of computers worldwide."
[9]Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild
[10]Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
[11]Qbot malware's back, and latest strain relies on Visual Basic script to slip into target machines
[12]Google launches lawsuit against a blockchain-enabled botnet
However, Check Point Research this month noted in announcing its March threat index that Emotet [13]returned in November 2021 and had gained momentum since the shutdown of the Trickbot botnet infrastructure in February. It is again the most prevalent malware.
"This was solidified even further [in March] as many aggressive email campaigns have been distributing the botnet, including various Easter-themed phishing scams exploiting the buzz of the festivities," the researchers wrote.
[14]
"These emails were sent to victims all over the world with one such example using the subject 'Buona Pasqua, happy easter,' yet attached to the email was a malicious XLS file to deliver Emotet." ®
Get our [15]Tech Resources
[1] https://www.checkpoint.com/press/2022/march-2022s-most-wanted-malware-easter-phishing-scams-help-emotet-assert-its-dominance/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YmF-tQJw9LpLFLvWqhWPRwAAAIY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.kaspersky.com/blog/qbot-emotet-spam-mailing/44144/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YmF-tQJw9LpLFLvWqhWPRwAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YmF-tQJw9LpLFLvWqhWPRwAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YmF-tQJw9LpLFLvWqhWPRwAAAIY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://twitter.com/Cryptolaemus1
[8] https://www.theregister.com/2021/01/27/emotet_botnet_taken_down_europol/
[9] https://www.theregister.com/2021/12/15/patch_tesuday/
[10] https://www.theregister.com/2021/04/26/emotet_sunday_25_april_killswitch_date/
[11] https://www.theregister.com/2019/02/28/new_qbot_banking_malware_strain/
[12] https://www.theregister.com/2021/12/08/google_blockchain_botnet_lawsuit/
[13] https://www.theregister.com/2021/11/16/emotet_botnet_rappears/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YmF-tQJw9LpLFLvWqhWPRwAAAIY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
the great misunderstood ?
The story says this bunch were established in Ukraine, not in Russia.
One of the languages used in the eMails is Russian.
Russia is not cut off from using FOSS solutions...........did someone forget that Russians can code as well, so why are they fucked up by the American (non socialist) software vendors pulling the rug ?
Fuck me, some of the facists (non socialist) company's which depend on this shit at this end could do with pulling the rug on their chosen vendors software ...............
When will the world WAKE UP
ALF
Re: the great misunderstood ?
Ukranian programmers have always been much better than Russian writers, so now that we are deleting *.ru emails and communications with the Ukraine have dropped 90% we may be seeing a slightly better world because we're having to write our own malware?
Re: the great misunderstood ?
Who know, maybe this will be the Year of Linux Desktop - at least in Russia. And if they lose the capability to develop on Windows - the better.
Still I guess there are a lot of Windows users in Russia too - they do like GUIs like anybody else.
I don't understand your "socialist" references - Putin & C. looks socialists like Mussolini was (who actually was a prominent Socialist before founding the Fascist Party...).
I wonder...
I wonder if Russia, having established itself as a safe haven for Malware authors, Ransomware gangs, and other online ne'er do wells, will before too long find itself the number one victim of these miscreants.
My thinking is that, with Russia effectively cut off from updates and security fixes from the major players, Russians will find themselves with highly outdated software and so highly vulnerable to any and all malware.
Will it be that Russia will begin to Reap what it has Sown? But not in the way it had hoped for?