ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Emotet is the most common malware

criticalMalwareimportance 60CVE-2017-11882

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11882
Memory Corruption RCE in Microsoft Office via Legacy Equation Editor

CVE-2017-11882 is a memory corruption vulnerability (CWE-119) in Microsoft Office, residing in the legacy Microsoft Equation Editor component (EQNEDT32.EXE), that allows remote code execution in the context of the current user. Attackers trigger it by persuading a user to open a crafted document, most commonly an RTF file or other Office document carrying a malicious embedded equation object, which overflows a buffer while the equation content is parsed. Successful exploitation lets the attacker run arbitrary code with the privileges of the signed-in user, a typical foothold for malware delivery and, per CISA, for ransomware operations. Any environment running affected Microsoft Office builds is exposed; the source data does not enumerate specific affected version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and holds a 99.9% EPSS score (percentile 100), though the source data lists no public PoC.

Do: Apply Microsoft's Office security updates (November 2017 or later) across all endpoints, prioritizing this KEV-listed flaw given its known ransomware use. On systems that cannot yet be patched, disable or unregister the legacy Equation Editor (EQNEDT32.EXE) and consider blocking or warning on RTF attachments as interim mitigations. Check for indicators of abuse such as EQNEDT32.EXE spawning unexpected child processes after document opens.

7.8100% KEV ransomware PoC ×10
  • Microsoft Office
masshundreds of millions of users/installations (Office is near-ubiquitous on Windows and in enterprises; the share still unpatched is unknown)
Full article842 words · extracted from helpnetsecurity.com · click to collapse

HP announced that the HP Wolf Security threat research team has identified a 27-fold increase in detections resulting from Emotet malicious spam campaigns in Q1 2022, compared to Q4 2021 – when Emotet first made its reappearance.

Emotet detections Q1 2022

The latest global HP Wolf Security Threat Insights Report – which provides analysis of real-world cybersecurity attacks – shows that Emotet has bolted up 36 places to become the most common malware family detected this quarter (representing 9% of all malware captured). One of these campaigns – which was targeted at Japanese organizations and involved email thread hijacking to trick recipients into infecting their PCs – was largely responsible for an 879% increase in .XLSM (Microsoft Excel) malware samples captured compared to the previous quarter.

By isolating threats that have evaded detection tools and made it to user endpoints, HP Wolf Security has specific insight into the latest techniques being used by cybercriminals. Notable examples include:

  • Stealthy alternatives to malicious Microsoft Office documents growing popular, as macros start being phased out: As Microsoft has begun disabling macros, HP has seen a rise in non-Office-based formats, including malicious Java Archive files (+476%) and JavaScript files (+42%) compared to last quarter. Such attacks are harder for organizations to defend against because detection rates for these file types are often low, increasing the chance of infection.
  • Signs indicate HTML smuggling on the rise: The median file size of HTML threats grew from 3KB to 12KB, suggesting a rise in the use of HTML smuggling, a technique where cybercriminals embed malware directly into HTML files to bypass email gateways and evade detection, before gaining access and stealing critical financial information. Recent campaigns were seen targeting Latin American and African banks.
  • “Two for One” malware campaign leads to multiple RAT infections: A Visual Basic script attack was found being used to kick start a kill chain resulting in multiple infections on the same device, giving attackers persistent access to victims’ systems with VW0rm, NjRAT and AsyncRAT.

“Our Q1 data shows this is by far the most activity we’ve seen from Emotet since the group was disrupted early in 2021 – a clear signal its operators are regrouping, building back their strength and investing in growing the botnet. Emotet was once described by CISA as among the most destructive and costly malware to remediate and its operators often collaborate with ransomware groups, a pattern we can expect to continue. So their reemergence is bad news for businesses and public sector alike,” explains Alex Holland, Senior Malware Analyst, HP Wolf Security threat research team, HP.

“Emotet also continued to favor macro-enabled attacks – perhaps to get attacks in before Microsoft’s April deadline, or simply because people still have macros enabled and can be tricked into clicking on the wrong thing.”

The findings are based on data from many millions of endpoints running HP Wolf Security. HP Wolf Security tracks malware by opening risky tasks in isolated, micro-virtual Machines (micro-VMs) to protect the user and understand and capture the full attempted infection chain, mitigating threats that have slipped past other security tools. To date, HP customers have clicked on over 18 billion email attachments, web pages, and downloads with no reported breaches. This data provides unique insights into how threat actors use malware in the wild.

Further key findings

  • 9% of threats hadn’t been seen before at the time they were isolated, with 14% of email malware isolated having bypassed at least one email gateway scanner.
  • It took over 3 days (79 hours), on average, to be known by hash to other security tools.
  • 45% of malware isolated by HP Wolf Security were Office file formats.
  • Threats used 545 different malware families in their attempts to infect organizations, with Emotet, AgentTesla and Nemucod being the top three.
  • A Microsoft Equation Editor exploit (CVE-2017-11882) accounted for 18% of all malicious samples captured.
  • 69% of malware detected was delivered via email, while web downloads were responsible for 18%. The most common attachments used to deliver malware were documents (29%), archives (28%), executables (21%), spreadsheets (20%).
  • The most common attachments used to deliver malware were spreadsheets (33%), executables and scripts (29%), archives (22%), and documents (11%).
  • The most common phishing lures were business transactions such as “Order”, “Payment”, “Purchase”, “Request” and “Invoice”.

“This quarter we saw a significant 27% rise in the volume of threats captured by HP Wolf Security. As cybercriminals tweak their approaches in response to changes in the IT landscape, the volume and variety of attacks continues to increase, and it becomes harder for conventional tools to detect attacks,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP.

“With an uptake in alternative file types and techniques being used to bypass detection, organizations need to change course and take a layered approach to endpoint security. By applying the principle of least privilege and isolating the most common threat vectors – from email, browsers, or downloads – rendering malware delivered via these vectors harmless. This dramatically reduces organizations’ risk exposure to cyber threats.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/05/17/emotet-detections-q1-2022/