Emotet on the move in a new dangerous variant

Emotet on the move in a new dangerous variant

Share post

After months of deceptive silence, a new dangerous variant of the Emotet Trojan has now been discovered. Hornetsecurity's Security Lab discovered it and warns against it. The new variant relies on large files that have been extremely packed to avoid fast scans.

The dangerous Emotet malware is back. After almost three months of silence, the Security Lab, Hornetsecurity's in-house security laboratory, has discovered a new variant of the Trojan. The latest version of Emotet uses very large files to bypass security scans and infiltrate IT systems. Security software often only scans the first bytes of large files - or lets them into the system without scanning them.

Emotet is in a large mail attachment

🔎 The spam emails contain a 600 KB ZIP file as an attachment, which in turn contain huge Word documents (.doc) of over 500 MB (Image: Hornetsecurity).

The spam emails contain a 600 KB ZIP file as an attachment, which in turn contains huge Word documents (.doc) of over 500 MB. If the attacked user opens one of the Word documents, a malicious payload in .dll format is immediately downloaded, which is also more than 500 MB in size.

The new Emotet variant is not yet very widespread, but the Security Lab assumes that it will soon spread very quickly. E-mails containing the Trojan can appear completely legitimate. Even if security systems filter out these emails and quarantine them, end users can release them again on their own and thus free them from the quarantine. But those who fall victim to the virus contribute significantly to its spread.

Extremely packed files bypass scan

IT administrators must therefore act immediately. On the one hand, they must urgently warn the workforce about this new danger. On the other hand, it is important to consistently block these malicious e-mails. Otherwise the company's success is in great danger. Hornetsecurity helps its customers to ward off such attacks by having Advanced Threat Protection reject such emails with immediate effect.

More at Hornetsecurity.com

 


About Hornetsecurity

Hornetsecurity is the leading German cloud security provider for e-mail in Europe and protects the IT infrastructure, digital communication and data of companies and organizations of all sizes. The security specialist from Hanover provides its services via 10 redundantly secured data centers around the world. The product portfolio includes all important areas of e-mail security, from spam and virus filters to legally compliant archiving and encryption, to defense against CEO fraud and ransomware. Hornetsecurity has around 200 employees at 12 locations around the world and operates with its international dealer network in more than 30 countries.


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more