Security researchers discovered a new variant of the Emotet malware family that employed a wireless local area network (WLAN) as its distribution method.

Binary Defense spotted this WLAN distribution method in a self-extracting RAR file containing two binaries. First, it used “worm.exe” as a setup file to prepare its Wi-Fi spreading activity. The executable analyzed by researchers contained a timestamp of April 16, 2018, which would suggest that attackers have been spreading Emotet via Wi-Fi for close to two years. Even so, Binary Defense’s data indicated that Emotet might not drop its worm.exe binary too frequently.

The campaign leveraged worm.exe to enumerate all Wi-Fi devices enabled on the local computer and to profile all existing Wi-Fi networks. At that point, it launched into its brute-forcing connection loops to try to connect to a network, enumerate all devices and brute-force passwords for all users. When successful, the campaign moved to “service.exe,” a binary that it used to create a connection with its command-and-control (C&C) server and ultimately drop an embedded Emotet executable.

A Look Back at Emotet’s Recent Activity

The attack described above is one of the latest episodes in Emotet’s ongoing evolution. In December 2019, for instance, Cisco Talos witnessed a surge of activity in which the malware family used emails to target individuals in the U.S. military and government. In February 2020, IBM X-Force reported that malicious actors used SMS messages to masquerade as banks in an attempt to deliver Emotet.

How to Defend Against WLAN Distribution Tactics

Security professionals can help defend against malware campaigns that use WLANs for distribution by changing the default passwords on their routers and enabling multifactor authentication (MFA) whenever possible. Given Emotet’s frequent use of malicious email attachments as an infection vector, infosec personnel should also implement proper logging with their security information and event management (SIEM) team to monitor for the activation of malicious macros.

More from

OneNote, Many Problems? The New Phishing Framework

There are plenty of phish in the digital sea, and attackers are constantly looking for new bait that helps them bypass security perimeters and land in user inboxes.Their newest hook? OneNote documents. First noticed in December 2022, this phishing framework has seen success in fooling multiple antivirus (AV) tools by using .one file extensions, and January 2023 saw an attack uptick as compromises continued.While this novel notes approach will eventually be phased out as phishing defenses catch up, current conditions…

When the Absence of Noise Becomes Signal: Defensive Considerations for Lazarus FudModule

In February 2023, X-Force posted a blog entitled “Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers” that details the capabilities of a sample attributed to the Lazarus group leveraged to impair visibility of the malware’s operations. This blog will not rehash analysis of the Lazarus malware sample or Event Tracing for Windows (ETW) as that has been previously covered in the X-Force blog post. This blog will focus on highlighting the opportunities for detection of the FudModule within the…

LastPass Breaches Cast Doubt on Password Manager Safety

In 2022, LastPass suffered a string of security breaches which sparked concern among cyber professionals and those impacted by the intrusions. Some called into question the way LastPass handled and responded to the incident. In addition, the situation ignited a wider conversation about the risks linked to utilizing password managers.A password manager helps users generate strong passwords and safeguards them within a digital locker. A master password secures all data, which enables users to conveniently access all their passwords for…

The Role of Finance Departments in Cybersecurity

Consumers are becoming more aware of the data companies collect about them, and place high importance on data security and privacy. Though consumers aren’t aware of every data breach, they are justifiably concerned about what happens to the data companies collect. A recent study of consumer views on data privacy and security revealed consumers are more careful about sharing data. The majority of respondents (87%) say they wouldn’t do business with companies that appear to have weak security. Study participants also…