Report: Emotet makes phishing lures more convincing by scraping victims' emails
Full article606 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers say Emotet is improving its ability to steal financial credentials by using emails scraped from its own victims to make templates.
Researchers from phishing protection company Cofense say that an active botnet spreading the Emotet banking trojan has significantly upgraded its ability to spoof financial organizations with convincing phishing lures.
The U.S. Computer Emergency Readiness Team (US-CERT) describes Emotet as “an advanced, modular banking Trojan” that is “among the most costly and destructive malware” for both public and private organizations.
In a report published Tuesday, Cofense says it has observed Geodo — another name for Emotet — using an new scraping feature that makes its better at impersonating organizations. The feature lifts templates stolen from infected victims, then uses the templates to upgrade its phishing campaigns a with credible aura of a financial institution, according to the report.
Previously known capabilities of Emotet’s spamming module include the ability to steal contact lists and email signatures, Cofense says. But in this campaign, researchers say there’s the added capability to scrape up to 16 kilobytes of “raw emails and threads.”
Aaron Higbee, co-founder and chief technology officer of Cofense, told CyberScoop in an email that this new module was added to Emotet Nov. 6, scraping email templates from old and new infected hosts.
“Cofense Intelligence assessed [the scraping functionality] would either be used to bolster the actors’ social engineering efforts, using the stolen data to refine Geodo phishing templates, or for direct revenue generation – selling the raw message content to the highest bidder,” the report says.
The emails observed by Cofense are made to look like banking statements and payment authorizations, among other things. But embedded in the emails are links that lead to Microsoft Word documents with malicious macros. If enabled, the macros drop Emotet onto the victim’s system, which is then able to download additional malware.
The IcedID banking trojan was the second payload for some instances in this campaign, Cofense says. Higbee said the malware is designed to steal credentials to the victim’s financial accounts. IceID bears similarity to Trickbot, another common banking trojan, but targets a broader range of financial information, including investment banking accounts, he said.
Cofense says it has been tracking Emotet activity for some months and that it “continues to grow.” The botnet’s clients have reportedly amassed 20,000 credentials and millions of email targets in the time that the company has tracked it.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/