Banks being targeted with major malware campaign

(Image credit: Shutterstock)

Following a brief break over the holidays, the Emotet malware has returned and is now being used by cybercriminals to target banks and financial institutions in the US and UK according to new research from Menlo Security.

While Emotet started out as a banking trojan and later evolved into a botnet, its creators are now leasing it out to others who wish to distribute their own malware. 

Emotet activity appeared to be in decline at the end of last year but unfortunately the malware resurfaced in January. Researchers at Menlo Security explained how Emotet is now being used in a new campaign to target banks and financial institutions in a blog post detailing their findings, saying:

“After taking a break through the holiday season in 2019, Emotet malware attacks have restarted in 2020, this time targeting the financial services industry. Similar to previous versions, the Emotet malware is only just the initial attack vector used to launch the attack. The attack is initiated with a malicious Microsoft Word document that is designed to be downloaded and opened by the user. Once opened, the malicious macro executes and contact is made with the command-and-control server to initiate the next stage of the attack.”

Emotet resurgence

According to Menlo Security, Emotet is now being used to launch attacks on organizations in the financial services industry as well as in smaller attacks targeting the food, media and transportation industries. Three quarters of the attacks have been aimed at organizations in the US and UK while the remaining attacks have targeted organizations in the Philippines, Spain and India.

As was the case with previous attacks, the malware is delivered via phishing emails that contain a malicious Microsoft Word document. However, the email subject lines have been altered to appeal directly to workers in the financial sector by including common financial terms.

The malicious Microsoft Word document attached to these emails says that users need to 'enable content' in order to view the document. Once a user does this, it allows malicious macros and URLs to deliver the Emotet malware to their computer.

Since Emotet is now also a botnet, these emails don't come from one source in particular but rather from other infected PCs around the world. Falling victim to this malware doesn't just provide an attacker with a backdoor into your system, it also allows them to use your PC to spread Emotet to other user's machines.

To prevent falling victim to Emotet, it is highly recommended that users pay close attention to any documents which ask them to enable macros, especially when they come in an email from an unknown source.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough