Cybercriminals currently distributing a new form of EMOTET malware that targets financial and banking services to steal sensitive information by injecting malicious code into the targeted computer.
The US-Cert team already issued an alert for an advanced Emotet malware attack that targets governments, private and public sectors in the most destructive way to steal various sensitive information.
Currently distributed campaign mainly targeting the Chile where it infects hundreds of users computers to access financial and banking services.
Attackers using various evasion technique including living off the land to bypasses Virus Total (VT) detentions.
Living off the land tactics is the use of operating system features, making use of tools already installed on targeted computers or legitimate network administration tools to compromise victims networks.
EMOTET Malware Infection Process
Initial stage of infection wave starts via malspam email campaign where attackers inserting malicious documents or URL links inside the body of an email sometimes disguised as an invoice or PDF attachment.
A malicious attachment identified as “__Denuncia_Activa_CL.PDF.bat” in email attachment with the obfuscated source code to evade antivirus detection and make it difficult to
Once the victim clicks and executes the .bat file, a Windows batch script will connect to the Command & Control (C&C) server to download the second script.
According to the research done by Pedro Tavares from
EMOTET malware packed with an extreme commercial packer dubbed Themida which makes very difficult to analyse by implementing the aditional layer of protection.
“Themida packer has a large group of specific features that are very appreciated by criminals to protect their threats. For example, it uses VM-protection techniques, debug-protection, virtual machine emulation, anti-monitors techniques, anti-memory patching
Along with this, malware authors included various additional modules to track the user’s geolocation and language preferences to narrow down their targets. By having the geolocation tracking functionality attackers particularly targeting the user’s from Spain/Chile.
After the complete infection process, Emotet
Chile, the USA, Germany, and France were the countries with most hits. From a total of 1089 infections, 175 victims were impacted in Chile, 162 in
For more details and complete analysis of this malicious campaign see the Technical Analysis here.
Indicators of compromise (IoCs)
Malware Payload (EMOTET):