There’s a reason your inbox has more malicious spam—Emotet is back

After taking a five-month break, the botnet returns with a short burst of activity. …

Robot hands work a laptop keyboard.reader comments

62 with 35 posters participating

Emotet, the world’s most costly and destructive botnet, returned from a five-month hiatus on Friday with a blast of malicious spam aimed at spreading a backdoor that installs ransomware, bank-fraud trojans, and other nasty malware.

The botnet sent a hefty 250,000 messages during the day, mostly to people in the United States and the United Kingdom, Sherrod DeGrippo, senior director of threat research and detection at security firm Proofpoint, told Ars. Other researchers said targets were also located in the Middle East, South America, and Africa. The botnet followed its characteristic pattern of sending either a malicious document or link to a malicious file that, when activated, installs the Emotet backdoor.

A map showing where Emotet hit on Friday.

Enlarge / A map showing where Emotet hit on Friday.

The botnet gave its first indications of a return on Tuesday, with small message volumes being sent out. Email samples that appeared on Twitter accounts from threat monitors abuse.ch and Spamhaus looked like this:

Emotet’s resurgence on Friday was also spotted by antivirus provider Malwarebytes and Microsoft.

Box of tricks

Emotet has proven to be one of the more resourceful threats to face people in recent years. Emails often appear to arrive from a person the target has corresponded with in the past. The malicious messages often use the subject lines and the

Continue reading – Article source

Similar Posts: