Tuesday, November 26, 2024
HomeComputer SecurityNew Wave of Emotet Malware Hacks Wi-Fi Networks to Attack New Victims

New Wave of Emotet Malware Hacks Wi-Fi Networks to Attack New Victims

Published on

A new wave of Emotet malware campaign With New Wi-Fi Spreader takes advantage of the wlanAPI interface to enumerate all Wi-Fi networks in the area and spreads the infection.

The Emotet is a banking Trojan detected in the year 2014, it was designed to steal sensitive and private information.

It is one of the most dangerous malware and it is capable of delivering payloads based on the specific tasks. It’s warm like capability helps to spread rapidly with other connected computers.

- Advertisement - SIEM as a Service

Malware Infection

Emotet primarily distributed through social engineering techniques such as the emails with the links to download the malware.

With the new Emotet campaign it arrives with a new Wi-Fi Spreader module downloads to the system C:\ProgramData. The downloaded binary contains a self-extracting RAR that has two (service.exe and worm.exe) binaries to spread the infection through WiFi.

Emotet wifi
Worm file Download

The worm.exe is the executable used for spreading the malware, once it executed it copies the service.exe to a variable for using it while spreading.

Then it calls wlanAPI.dll class that used by Native Wi-Fi to manage the wireless network profiles and connections for spreading the infection to other networks.

Emotet wifi
Emotet Wifi Distribution

“The Worm enumerates all Wi-Fi devices currently enabled on the local computer, which it returns in a series of structures. These structures contain all the information relating to the Wi-Fi device, including the device’s GUID and description,” read the Binary Defense analysis.

It gathers possible information from every available Wi-Fi network present in the list of networks.

Breaking Weak Wi-Fi Network

Once the connection established with the Wi-Fi network it enumerates users and attempts brute-force for all users on the network.

Next, the Service.exe is the payload installed by worm.exe on the machine, once installed it communicates with the C2 server and executes the binary embedded in service.exe.

Previously Emotet known to distributed only through malspam and infected networks, with this new loader it spreads through nearby wireless networks that use weak passwords.

IOCs

9.file            865cf5724137fa74bd34dd1928459110385af65ffa63b3734e18d09065c0fb36
Worm.exe 077eadce8fa6fc925b3f9bdab5940c14c20d9ce50d8a2f0be08f3071ea493de8
Service.exe 64909f9f44b02b6a4620cdb177373abb229624f34f402335ecdb4d7c8b58520b
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Dell Wyse Management Suite Vulnerabilities Let Attackers Exploit Affected Systems Remotely

Dell Technologies has released a security update for its Wyse Management Suite (WMS) to...

CISA Details Red Team Assessment Including TTPs & Network Defense

The Cybersecurity and Infrastructure Security Agency (CISA) recently detailed findings from a Red Team...

IBM Workload Scheduler Vulnerability Stores User Credentials in Plain Text

IBM has issued a security bulletin warning customers about a vulnerability in its Workload...

Multiple Flaws With Android & Google Pixel Devices Let Attackers Elevate Privileges

Several high-severity vulnerabilities have been identified in Android and Google Pixel devices, exposing millions...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...