This notorious malware steals your email attachments to attack your friends Email client


After adding a Wi-Fi worm module to hack wireless networks earlier this year, the operators of the Emotet malware are now using stolen attachments to help increase the authenticity of the spam emails they use to infect users’ systems.
As reported by BleepingComputer, this is the first time the botnet has used stolen attachments to add credibility to emails through the use of an attachment stealer module that was added to the malware around June 13th, according to Marcus Hutchins.
When it was first discovered all the way back in 2014, Emotet was originally a banking trojan. However, now it has evolved into a malware botnet which is used by attackers to download other malware families such as Trickbot and the QakBot trojan.
Cofense Labs also confirmed that Emotet is now leveraging stolen attachments in a post on Twitter, which reads:
“Emotet seems to be using not only stolen email bodies, but is now including stolen attachments as well. This lends to even more authenticity in their phishing emails. In one example we found 5 benign attachments and a dropper link within the templated portion of the email.”
Return of Emotet
Following more than five months of inactivity, Emotet resumed its operations on July 17 and since then, the botnet has been sending out malicious spam emails disguised as payment reports, invoices, job opportunities and shipping information through all of its server clusters.
Since its return, the malware has been used to install TrickBot on Windows systems and spread the QakBot malware which replaced its initial TrickBot payloads. Government agencies around the world have also started warning businesses and consumers about the dangers Emotet poses with both the Australian Cyber Security Centre (ACSC) and the Cybersecurity and Infrastructure Security Agency (CISA) both issuing separate warnings about the malware.
Using stolen attachments to make its malicious emails appear more legitimate is certainly a clever tactic and email security solutions will likely have a harder time distinguishing between real emails and spam emails using legitimate attachments as a disguise.
Now that Emotet has once again updated its tactics to better avoid detection and attack more users, organizations and individuals should be extra cautious when checking their email and avoid opening any attachments from unknown senders.
Via BleepingComputer
After adding a Wi-Fi worm module to hack wireless networks earlier this year, the operators of the Emotet malware are now using stolen attachments to help increase the authenticity of the spam emails they use to infect users’ systems. As reported by BleepingComputer, this is the first time the botnet…
Recent Posts
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
- Lenovo is going all out with yet another funky laptop design: this time, it’s a business notebook with a foldable OLED screen
- Elon Musk’s first month of destroying America will cost us decades
- The first iOS 18.4 developer beta is here, with support for Priority Notifications
- Fortnite’s new season leans heavily on heist mechanics
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010