Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Will Mercury In Retrograde Bring A Mood Shift In Bitcoin? bitcoin news
  • SEC Drops the Ball on Crypto Regulation and There Are Long-Term Consequences, Says Commissioner – Regulation Bitcoin News bitcoin news
  • Will Bitcoin Shoot Over $40,000 — Or Drop To $35,000? bitcoin news
  • 9 out of 10 Central Banks Worldwide Are Exploring Digital Currencies — Driven by Crypto Market – Featured Bitcoin News bitcoin news
  • The Added Dangers Privileged Accounts Pose to Your Active Directory cyber security news
  • BTC Drops Below $29,000 to Start the Weekend – Market Updates Bitcoin News bitcoin news
  • Global Metaverse Event of Lydian․World in Dubai Opera 7th May 2022 bitcoin news
  • A Dot Com Magnitude Crash To Rock The Crypto Market? bitcoin news

Emotet Testing New Delivery Ideas After Microsoft Disables VBA Macros by Default

Posted on May 2, 2022 By root


Emotet

The threat actor behind the prolific Emotet botnet is testing new attack methods on a small scale before co-opting them into their larger volume malspam campaigns, potentially in response to Microsoft’s move to disable Visual Basic for Applications (VBA) macros by default across its products.

Calling the new activity a “departure” from the group’s typical behavior, Proofpoint alternatively raised the possibility that the latest set of phishing emails distributing the malware show that the operators are now “engaged in more selective and limited attacks in parallel to the typical massive scale email campaigns.”

Emotet, the handiwork of a cybercrime group tracked as TA542 (aka Mummy Spider or Gold Crestwood), staged a revival of sorts late last year after a 10-month-long hiatus following a coordinated law enforcement operation to take down its attack infrastructure.

Emotet

Since then, Emotet campaigns have targeted thousands of customers with tens of thousands of messages in several geographic regions, with the message volume surpassing over one million per campaign in select cases.

The new “low volume” email campaign analyzed by the enterprise security firm involved the use of salary-themed lures and OneDrive URLs hosting ZIP archives that contain Microsoft Excel Add-in (XLL) files, which, when executed, drop and run the Emotet payload.

The new set of social engineering attacks is said to have taken place between April 4, 2022, and April 19, 2022, when other widespread Emotet campaigns were put on hold.

CyberSecurity

The absence of macro-enabled Microsoft Excel or Word document attachments is a significant shift from previously observed Emotet attacks, suggesting that the threat actor is pivoting away from the technique as a way to get around Microsoft’s plans to block VBA macros by default starting April 2022.

The development also comes as the malware authors last week fixed an issue that prevented potential victims from getting compromised upon opening the weaponized email attachments.

“After months of consistent activity, Emotet is switching things up,” Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, said.

“It is likely the threat actor is testing new behaviors on a small scale before delivering them to victims more broadly, or to distribute via new TTPs alongside its existing high-volume campaigns. Organizations should be aware of the new techniques and ensure they are implementing defenses accordingly.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Microsoft Discovers New Privilege Escalation Flaws in Linux Operating System
Next Post: North Korean Hackers Target Journalists with GOLDBACKDOOR Malware

Related Posts

  • Watch Out! Hackers Begin Exploiting Recent Zyxel Firewalls RCE Vulnerability cyber security news
  • Microsoft Azure Vulnerability Exposes PostgreSQL Databases to Other Customers cyber security news
  • Experts Analyze Conti and Hive Ransomware Gangs Chats With Their Victims cyber security news
  • Microsoft Finds Critical Bugs in Pre-Installed Apps on Millions of Android Devices cyber security news
  • Which Hole to Plug First? Solving Chronic Vulnerability Patching Overload cyber security news
  • Google to Add Passwordless Authentication Support to Android and Chrome cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News
  • India’s Central Bank RBI to Adopt a ‘Graded Approach’ to Digital Currency Launch – Regulation Bitcoin News
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin?
  • We’re Approaching a Recession but It’s ‘Actually a Good Thing’ – Economics Bitcoin News
  • FTX CEO Says Crypto Exchange Is Ready to Spend Billions on Acquisition Deals – Bitcoin News

Recent Comments

No comments to show.
  • Samsung Group Investment Arm to List Blockchain ETF on Hong Kong Exchange – Finance Bitcoin News bitcoin news
  • Researchers Find Backdoor in School Management Plugin for WordPress cyber security news
  • As BTC Slides Toward Resistance, the Chance of a Rare Triple Top Formation Comes Into Play – Markets and Prices Bitcoin News bitcoin news
  • Android and Chrome Users Can Soon Generate Virtual Credit Cards to Protect Real Ones cyber security news
  • Finance School Bentley University Now Accepts Cryptocurrency Payments for Tuition – Bitcoin News bitcoin news
  • Hackers Trick Users with Fake Windows 11 Downloads to Distribute Vidar Malware cyber security news
  • U.S. Offers $10 Million Bounty for Information on 6 Russian Military Hackers cyber security news
  • Robinhood Launching New Non-Custodial Web3 Crypto Wallet – Wallets Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme