Emotet has returned with additional modules that have been specifically designed to improve the malware’s evasion capabilities, a cybersecurity researcher warned.

In a Twitter thread this past Saturday, IT security expert Marcus Hutchins, known as MalwareTech, said botnets that have been dormant for several months have been reactivated.

One botnet he described as E2, for example, has a module designed to steal email data, while another targets system credentials. Although it originally emerged as a banking Trojan akin to Trickbot and has already been rewritten several times before, Hutchins noted Emotet appears to have undergone a complete overhaul.

Hashbusting Comes Into Play

Among the techniques embedded into botnet E2’s modules is hashbusting. By making sure each malware’s file hash looks different on every system it infects, it becomes more difficult to track it, Hutchins explained.

The cybercriminals behind the variant have also made it simpler to mutate the malware by obfuscating code flow via a state machine, he added.

This means a randomized state value can control the flow of code blocks. They are placed in an arbitrary manner, increasing the challenges for security leaders and their teams. The malware’s authors achieve this by flattening the branches into nested loops.

All this means whoever updated the malware may be getting ready to launch an attack campaign, Hutchins concluded.

Emotet has emerged as a popular tool for hackers. Earlier this month, Microsoft reported an attack where the malware brought down an entire network. In February, another variant was using wireless local area networks (WLANs) as a distribution method.

Protect Yourself From Emotet Variants

Like many similar cyberthreats, Emotet has largely been driven by phishing emails that trick victims into clicking on a link that launches the malware.

While security awareness training can help here, IT security teams can improve their odds of detecting suspicious activity by using the logging and alerting capabilities of a security information and event management (SIEM) solution. Deploying multifactor authentication (MFA) is another best practice worth applying.

More from

2022 Industry Threat Recap: Finance and Insurance

The finance and insurance sector proved a top target for cybersecurity threats in 2022. The IBM Security X-Force Threat Intelligence Index 2023 found this sector ranked as the second most attacked, with 18.9% of X-Force incident response cases. If, as Shakespeare tells us, past is prologue, this sector will likely remain a target in 2023. Finance and insurance ranked as the most attacked sector from 2016 to 2020, with the manufacturing sector the most attacked in 2021 and 2022. What…

X-Force Prevents Zero Day from Going Anywhere

This blog was made possible through contributions from Fred Chidsey and Joseph Lozowski. The X-Force Vulnerability and Exploit Database shows that the number of zero days being released each year is on the rise, but X-Force has observed that only a few of these zero days are rapidly adopted by cyber criminals each year. While every zero day is important and organizations should still devote efforts to patching zero days once a patch is released, there are characteristics of certain…

And Stay Out! Blocking Backdoor Break-Ins

Backdoor access was the most common threat vector in 2022. According to the 2023 IBM Security X-Force Threat Intelligence Index, 21% of incidents saw the use of backdoors, outpacing perennial compromise favorite ransomware, which came in at just 17%. The good news? In 67% of backdoor attacks, defenders were able to disrupt attacker efforts and lock digital doorways before ransomware payloads were deployed. The not-so-great news? With backdoor access now available at a bargain price on the dark web, businesses…

Hack-for-Hire Groups May Be the New Face of Cybercrime

Google’s Threat Analysis Group (TAG) recently released a report about growing hack-for-hire activity. In contrast to Malware-as-a-Service (MaaS), hack-for-hire firms conduct sophisticated, hands-on attacks. They target a wide range of users and exploit known security flaws when executing their campaigns. “We have seen hack-for-hire groups target human rights and political activists, journalists and other high-risk users around the world, putting their privacy, safety and security at risk,” Google TAG says. “They also conduct corporate espionage, handily obscuring their clients’ role.”…