Banks being targeted with major malware campaign

(Image credit: Shutterstock)

Following a brief break over the holidays, the Emotet malware has returned and is now being used by cybercriminals to target banks and financial institutions in the US and UK according to new research from Menlo Security.

While Emotet started out as a banking trojan and later evolved into a botnet, its creators are now leasing it out to others who wish to distribute their own malware. 

Emotet activity appeared to be in decline at the end of last year but unfortunately the malware resurfaced in January. Researchers at Menlo Security explained how Emotet is now being used in a new campaign to target banks and financial institutions in a blog post detailing their findings, saying:

“After taking a break through the holiday season in 2019, Emotet malware attacks have restarted in 2020, this time targeting the financial services industry. Similar to previous versions, the Emotet malware is only just the initial attack vector used to launch the attack. The attack is initiated with a malicious Microsoft Word document that is designed to be downloaded and opened by the user. Once opened, the malicious macro executes and contact is made with the command-and-control server to initiate the next stage of the attack.”

Emotet resurgence

According to Menlo Security, Emotet is now being used to launch attacks on organizations in the financial services industry as well as in smaller attacks targeting the food, media and transportation industries. Three quarters of the attacks have been aimed at organizations in the US and UK while the remaining attacks have targeted organizations in the Philippines, Spain and India.

As was the case with previous attacks, the malware is delivered via phishing emails that contain a malicious Microsoft Word document. However, the email subject lines have been altered to appeal directly to workers in the financial sector by including common financial terms.

The malicious Microsoft Word document attached to these emails says that users need to 'enable content' in order to view the document. Once a user does this, it allows malicious macros and URLs to deliver the Emotet malware to their computer.

Since Emotet is now also a botnet, these emails don't come from one source in particular but rather from other infected PCs around the world. Falling victim to this malware doesn't just provide an attacker with a backdoor into your system, it also allows them to use your PC to spread Emotet to other user's machines.

To prevent falling victim to Emotet, it is highly recommended that users pay close attention to any documents which ask them to enable macros, especially when they come in an email from an unknown source.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Latest in News
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
A mockup of the possible Apple M3 Ultra logo
Performance isn't the only reason you should buy Apple's M3 Ultra Mac Studio - it's reportedly one of the most power-efficient processors too
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet