Botnet that knows your name and quotes your email is back with new tricks

A botnet that knows your name and quotes your email is back with a new trick

Getty Images

Widely regarded as one of the biggest threats on the Internet, the Emotet botnet is back after a months-long hiatus with some new tricks.

Last week, Emotet debuted for the first time this year after four months. It’s a wave of malicious spam her messages that appear to come from known contacts, name recipients, and reply to an existing email her thread, that trademark her I’m back with activities. New techniques designed to evade endpoint security products and trick users into clicking links or enabling dangerous macros in attached Microsoft Office documents when Emotet returns from a previous hiatus was brought. Last week’s resumption of activities was no exception.

For example, a malicious email sent last Tuesday included a Word document with a large amount of extraneous data appended to the end. The resulting file was over 500MB in size, large enough to prevent some security products from scanning the contents. This technique, called binary padding or file pumping, works by adding zeros to the end of the document. If someone is tricked into enabling macros, the malicious Windows DLL file delivered will also be pumped, jumping from 616kB to 548.1MB, researchers at security firm Trend Micro said Monday.

Another evasive trick found in the attached document: Excerpt from a classic novel by Herman Melville Moby Dick, the text is unreadable because it appears in white font on top of a white page. Some security products automatically flag Microsoft Office files that contain only macros and images. Invisible text is designed to evade such software without arousing suspicion of the target.

deep instinct

When the Word document is opened, a graphic is displayed stating that the content cannot be accessed unless the user clicks the “Enable Content” button. Last year, Microsoft started disabling macros downloaded from the internet by default.

A graphic that appears immediately after opening a malicious Word document.It says I can't access the content "enable content" button is clicked.
Expanding / A graphic that appears immediately after opening a malicious Word document. It says you can’t access the content unless you click the Enable Content button.

trend micro

Click the Enable Content button to revert that default and allow macros to run. This macro causes Office to download a .zip file from a hacked legitimate website. Office then unzips the archive file and runs his inflated Emotet DLL to infect the device.

After infecting a victim’s device, the malware steals passwords and other sensitive data and uses the device to send malicious spam to other users. This malware can also download additional malware such as Ryuk ransomware and TrickBot malware. The infection chain looks like this:

trend micro

The attention to detail seen in this latest revival is Emotet’s hallmark behavior. For years, botnets have carefully copied email conversations received from infected machines and embedded them in malicious spam sent to other parties in the thread. By following up on emails from someone the target has communicated with in the past, malicious spam her messages are more likely to go undetected. Emotet can also gain access to Wi-Fi networks and infect connected devices.

With the return of Emotet, be wary of malicious emails that appear to come from trusted sources, call targets by name, or contain previously sent or received emails. is needed. There are few good reasons to enable macros in emailed documents. You must refuse to do so without first communicating with the sender by any medium other than telephone, instant message, or email.

Countries hardest hit by the latest Emotet run are Europe, Asia Pacific, and Latin America.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *