This nasty malware has disguised itself as a Windows 10 update

(Image credit: Shutterstock)

Emotet, the malware campaign that has been causing havoc for computer systems all over the world, has reappeared with a new approach to infecting devices. An email attachment claiming to be from Windows Update and instructing users to upgrade Microsoft Word is now being used to lure unsuspecting victims into downloading the malicious software. 

The malware works by first sending spam emails that contain either a Word document attachment or a download link. Victims will then be prompted to ‘Enable Content’ to allow macros to run on their device, which will install the Emotet Trojan.

The new document template being used to trick victims into downloading these macros takes the guise of a Windows Update message. Previous Emotet templates have purported to be from Windows 10 Mobile, Office 365 and the Widows Office Activation Wizard.

Guess who’s back?

Emotet has been one of the most prevalent online threats since at least last year and one of the ways that it has achieved its longevity is by subtly shifting its method of attack. Earlier this month, the malware entered the political arena by piggybacking on the US presidential election in order to dupe potential victims.

Although when Emotet was initially discovered it operated as a banking trojan, today it is more commonly used as a method to distribute other malware strains, including Trickbot, QBot and related ransomware. Its ability to evade detection makes it one of the most effective malware campaigns of recent times.

With the recent Emotet resurgence, online users need to be particularly vigilant against malicious spam emails. It’s good practice to never open an email unless it’s from a trusted sender and to always ensure that your security software is up-to-date. And with regard to Emotet specifically, if you receive an email attachment asking you to enable macros on Microsoft Word, it’s probably best to ignore it.

Via BleepingComputer

TOPICS
Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras