The actors behind the Emotet botnet ended a four-month hiatus by launching a malspam campaign targeting Polish- and German-speaking users.

According to ZDNet, security researcher Raashid Bhat spotted the Emotet botnet distributing new spam emails beginning on Sept. 16. Those emails contained malware-laden attachments and URLs that linked to malicious downloads. Users who downloaded or executed one of the malicious files associated with the campaign exposed themselves to the malware.

Upon completion of a successful infection, the threat enlisted each victim’s computer into a botnet that serves as a malware-as-a-service (MaaS) for attackers. Many bad actors have already leveraged this functionality to target the networks of enterprises and local governments with a variety of malicious software, especially samples of the BitPaymer and Ryuk ransomware families.

A Look Back at the Recent History of Emotet

Despite its four-month hiatus, Emotet made headlines throughout the first half of 2019. In February, researchers at Menlo Security spotted a spate of new attack campaigns that distributed the malware via URLs hosted on attacker infrastructure and traditional spam email attachments.

A couple of months later, Minerva Labs spotted the threat leveraging stolen email threads as a means of distribution. Shortly thereafter, Bleeping Computer reported on Emotet’s use of compromised connected devices as proxy command-and-control (C&C) servers. But then the malware suddenly went quiet, with Check Point not detecting any new campaigns for the majority of June.

How to Defend Against Phishing-Borne Malware

Security professionals can help defend their organizations against phishing-borne malware by integrating phishing intelligence into their security information and event management (SIEM) solution to vet attack campaigns such as spam operations. Companies should also help create an ongoing security awareness training program as part of a layered approach to maintaining their organization’s email security.

More from

Bridging the 3.4 Million Workforce Gap in Cybersecurity

As new cybersecurity threats continue to loom, the industry is running short of workers to face them. The 2022 (ISC)2 Cybersecurity Workforce Study identified a 3.4 million worldwide cybersecurity worker gap; the total existing workforce is estimated at 4.7 million. Yet despite adding workers this past year, that gap continued to widen.Nearly 12,000 participants in that study felt that additional staff would have a hugely positive impact on their ability to perform their duties. More hires would boost proper risk…

The Evolution of Antivirus Software to Face Modern Threats

Over the years, endpoint security has evolved from primitive antivirus software to more sophisticated next-generation platforms employing advanced technology and better endpoint detection and response.  Because of the increased threat that modern cyberattacks pose, experts are exploring more elegant ways of keeping data safe from threats.Signature-Based Antivirus SoftwareSignature-based detection is the use of footprints to identify malware. All programs, applications, software and files have a digital footprint. Buried within their code, these digital footprints or signatures are unique to the respective…

How Do Threat Hunters Keep Organizations Safe?

Neil Wyler started his job amid an ongoing cyberattack. As a threat hunter, he helped his client discover that millions of records had been stolen over four months. Even though his client used sophisticated tools, its threat-hunting technology did not detect the attack because the transactions looked normal. But with Wyler’s expertise, he was able to realize that data was leaving the environment as well as entering the system. His efforts saved the company from suffering even more damage and…

The White House on Quantum Encryption and IoT Labels

A recent White House Fact Sheet outlined the current and future U.S. cybersecurity priorities. While most of the topics covered were in line with expectations, others drew more attention. The emphasis on critical infrastructure protection is clearly a top national priority. However, the plan is to create a labeling system for IoT devices, identifying the ones with the highest cybersecurity standards. Few expected that news. The topic of quantum-resistant encryption reveals that such concerns may become a reality sooner than…