Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

1/3/2019
06:05 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Emotet Malware Gets More Aggressive

Emotet's operators have been adding new capabilities, making the malware now even more dangerous to its enterprise targets.

Emotet, a nasty botnet and popular malware family, has proven increasingly dangerous over the past year as its operators adopt new tactics. Now armed with the ability to drop additional payloads and arriving via business email compromise (BEC), it's become a major threat to organizations.

Security watchers are wary of Emotet, which was among the first botnets to spread banking Trojans laterally within target organizations, making removal difficult. Emotet first appeared in 2014 as a Trojan designed to snatch banking credentials and other sensitive data. The threat was frequently spread via phishing emails packed with malicious documents or links.

Over time, Emotet's operators - a group called Mealybug - have evolved its business model and the shape of their attack from a banking Trojan to a means of delivering other groups' threats. In 2018, Webroot dubbed Emotet the year's worst botnet seen distributing banking Trojans.

"Its information stealing payloads are delivered at an impressive pace, suggesting threat actors have automated multiple steps in their campaign operations," Webroot researchers write in a blog post on their rankings of 2018's worst threats. The changes to Emotet, while gradual at first, quickly ramped up in recent years as attackers switched to even more nefarious tactics.

After a quiet period in 2015, Emotet detections spiked in the second half of 2017, Symantec reported. Mealybug's victims expanded that year to include targets in Canada, China, Mexico, and the UK. Toward the end of 2017, the Cylance Threat Research Team analyzed a malicious Microsoft Word file with a malicious macro program created to download Emotet malware.

Taking on New Threats

In 2018, Mealybug ramped up its activity to the point where it was selling malware to other actors, says Sig Murphy, managing director of incident response and forensics at Cylance. Emotet was combined with Trickbot and Qakbot, a tactic Symantec also had detected in Feb. 2018. The blend of Emotet with other strains of ransomware made the threat more dangerous.

"The combination there is really hard to defend against properly because the loader is polymorphic," says Murphy. "It changes every time it infects a computer."

US-CERT issued an alert for Emotet in July 2018, calling it an advanced modular banking Trojan that mainly functions as a downloader or dropper of other banking Trojans. Emotet is "the most costly and destructive malware affecting state, local, tribal, and territorial (SLTT) governments, and the private and public sectors," it says, costing governments up to $1M per incident.

This hybrid threat model "is a unique challenge" to organizations, Murphy says, and catches many off guard. Emotet alone used to drop its own Emotet-branded malware. Later in the year, it was used to deliver new types of threats. Before, it would collect email credentials and use them to spread laterally. It later became interested in the content of targeted emails, he adds.

"It's pretty clear they're trying to pivot into [the] BEC attack model, which is different from what they've done in the past," says Murphy of the Mealybug threat group's evolving strategies. In August 2018, Trend Micro pick up on Spoofed banking emails arriving with Emotet malware. For example, spam emails contain payment notifications from spoofed bank email addresses. The email's body has a link to download a .doc file, which contains macros that, when run, activate a PowerShell command that downloads and runs the Emotet malware, researchers explain. 

After ramping up in early 2018, Murphy says Emotet increased again during the holiday season. Through the start of 2019, the malware continued to spread, and new enterprise clients were asking Cylance for help after getting infected, he says. Its growth signifies greater maturity among the Mealybug actors as they learn what's effective.

"They seem much more organized than a lot of other groups," Murphy explains. "The shift [to BEC] says they're continuing to be more organized … they know what's working and what's not." New ransomware variants like Qakbot provide a new source of income, he adds.

Thinking Ahead of the Attackers

It's hard to tell what Mealybug will do next. One route they could take, says Murphy, is attempt to make their attacks quieter. While he has no indication they might do this, he points out how Emotet in its current form is "very noisy" in its spread. If they could change the threat so it spreads without taking down systems, it would be harder to know a business is at risk.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
0%
100%
REISEN1955,
User Rank: Ninja
1/9/2019 | 7:10:42 AM
For a bit of humor
Which we all need from time to time.  Doesn't Emotet sounds like somebody buried in the Valley of the Kings in Egypt?
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
6 Small-Business Password Managers
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/8/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18980
PUBLISHED: 2019-11-14
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The o...
CVE-2019-17391
PUBLISHED: 2019-11-14
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and sec...
CVE-2019-18651
PUBLISHED: 2019-11-14
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document to a user that the website trusts. The user needs to have ...
CVE-2019-18978
PUBLISHED: 2019-11-14
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2019-14678
PUBLISHED: 2019-11-14
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects t...