Email Malware Returns With New Tricks
A notorious botnet that spreads malware through fake emails is back in action. Emotet has returned with some new tactics to try to bypass security checks.
Emotet had already gained a reputation for being (comparatively) successful at fooling humans and computers alike. Its most notable characteristic was that it not only used messages that appeared to come from a trusted contact, but that it addressed the recipient by name and even appeared to be a reply to a previous genuine message.
Most commonly, Emotet sends malware through Microsoft Word documents with macros. These are now disabled by default by Microsoft for any document received over the Internet. Posing as a trusted contact is intended to make it more likely the user will enable the macro.
Files Inflated
Now Trend Micro says Emotet's operators are using several new tactics, including those copied from other attackers and those which are more original. One is to "pad" the code behind the documents and associated malware to artificially inflate the file size to 500 megabytes or more.
That doesn't necessarily cause a notable delay in viewing, opening or downloading the files for recipients with fast broadband connections. However, it is enough to stop some security software from scanning the file. (Source: trendmicro.com)
The scammers have also found a creative solution to a common dilemma faced by malware distributors. Making the document blank means there's no need to create fake text that could easily raise suspicion unless individually crafted to match the recipient and supposed sender.
However, many anti-malware tools will automatically flag up a document that is empty but includes attachments or macros.
Classic Literature Hidden
The solution in this case is to put generic text on the page in a white font so that it's invisible to the user but not to the security software. In one example seen by Trend Micro, the hidden text was simply an excerpt from Moby Dick. (Source: arstechnica.com)
It's an old trick previously seen on websites that wanted to fool primitive search engine rankings by simply repeating a phrase over and over without it being spotted by the reader.
As always, the best things users can do is keep software (including security tools) up-to-date with security patches and to be wary of any unexpected documents or links. When uncertain, it's best to double-check with the supposed sender to make sure a document is legitimate.
What's Your Opinion?
Do you think twice before opening attachments or links? Have you noticed any requests to enable macros in a document? Are you confident in your security tools (including those built in to email services) to keep your device safe?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.