The Emotet virus is making a comeback and could be even more dangerous than before

Share This Post

“At around 21:26 UTC on Sunday, November 14th, we observed on some of our Trickbot trackers that bots attempted to download DLLs onto their systems. Internal processing identified these DLLs as Emotet. Resurrected from the dead. Emotet malware has become the solution of choice for cybercriminals who use their infrastructure to access targeted systems on a global scale. The operators then sold this access to other cybercrime groups to deploy ransomware such as Ryuk, Conti, ProLock and Egregor.

Cybersecurity experts have once again started watching threat actors drop malware  to revive the infamous Emotet botnet. This year, in January, European and North American law enforcement agencies joined forces to sabotage and bring down the Emotet botnet. However, several security his vendors and experts have found activity indicating an imminent resurgence of Emotet, including Cryptolaemus, GData, and Advanced Intel.

Highlights

  • Order count went from 3-4 to 7. The downloaded binary seems to have different execution options (these are just DLL). The researchers saw no evidence of the Emotet botnet spamming or finding malicious documents dropping malware, but added that it’s just a matter of time.

  • BleepingComputer reports on the development and, in a clear shift in tactics, the threat actors behind Emotet’s resurgence are now using a method called “Operation Reach Rounds” to replace existing TrickBot reconstructions. It points out that the infrastructure is being used to infiltrate the Emotet botnet. The Emotet research group, Cryptolaemus, began analyzing his new Emotet loader and noticed a change from the past. “So far I can definitely see that the command buffer has changed.

Read More:

Partnership Between Mitsubishi Electric and Nozomi Networks Strengthens Operational Technology Security Business

Mitsubishi Electric and Nozomi Networks Partnership Mitsubishi Electric and Nozomi...

Solidion Technology Inc. Completes $3.85 Million Private Placement Transaction

**Summary:** 1. Solidion TechnologyInc. has announced a private placement deal...

Analyzing the Effects of the EU’s AI Act on Tech Companies in the UK

Breaking Down the Impact of the EU’s AI Act...

Tech in Agriculture: Roundtable Discusses Innovations on the Ranch

Summary of Tech on the Ranch Roundtable Discussion: ...

Are SMEs Prioritizing Tech Investments Over Security Measures?

SMEs Dive Into Tech Investments, But Are...

Spotify Introduces Music Videos for Premium Members in Chosen Markets

3 Summaries of Spotify Unveils Music Videos for Premium...

Shearwater to Monitor Production at Equinor’s Two Oil Platforms

Shearwater GeoServices secures 4D monitoring projects from Equinor for...

Regaining Europe’s Competitive Edge in Innovation: Addressing the Innovation Lag

Europe’s Innovation Lag: How Can We Regain Our Competitive...

Related Posts

Government Warns of AI-Generated Content: Learn More about the Issue

Government issued an advisory on AI-generated content. All AI-generated content...

Africa Faces Internet Crisis: Extensive Outage Expected to Last for Months, Hardest-Hit Nations Identified

Africa’s Internet Crisis: Massive Outage Could Last Months, These...

FTC Investigates Reddit for AI Content Licensing Practices

FTC is investigating Reddit's plans...

Journalists Criticize AI Hype in Media

Summary Journalists are contributing to the hype and...