Thursday, March 6, 2025
HomeComputer SecurityNew Wave of EMOTET Malware Steals Financial Information by Injecting Malicious Code...

New Wave of EMOTET Malware Steals Financial Information by Injecting Malicious Code into Computer

Published on

SIEM as a Service

Follow Us on Google News

Cybercriminals currently distributing a new form of EMOTET malware that targets financial and banking services to steal sensitive information by injecting malicious code into the targeted computer.

The US-Cert team already issued an alert for an advanced Emotet malware attack that targets governments, private and public sectors in the most destructive way to steal various sensitive information.

Currently distributed campaign mainly targeting the Chile where it infects hundreds of users computers to access financial and banking services.

Attackers using various evasion technique including living off the land to bypasses Virus Total (VT) detentions.

Living off the land tactics is the use of operating system features, making use of tools already installed on targeted computers or legitimate network administration tools to compromise victims networks.

EMOTET Malware Infection Process

Initial stage of infection wave starts via malspam email campaign where attackers inserting malicious documents or URL links inside the body of an email sometimes disguised as an invoice or PDF attachment.

A malicious attachment identified as “__Denuncia_Activa_CL.PDF.bat” in email attachment with the obfuscated source code to evade antivirus detection and make it difficult to analyse.

Once the victim clicks and executes the .bat file, a Windows batch script will connect to the Command & Control (C&C) server to download the second script.

According to the research done by Pedro Tavares from segurancainformatica reported to “GBHackers On Security” “The latter leverages the WinRar/Ace vulnerability (CVE-2018-20250) dropping the malware itself into the Windows startup folder. Next, the infected machine will reboot and malware becomes persistent in the system startup.”

EMOTET malware packed with an extreme commercial packer dubbed Themida which makes very difficult to analyse by implementing the aditional layer of protection.

Themida packer has a large group of specific features that are very appreciated by criminals to protect their threats. For example, it uses VM-protection techniques, debug-protection, virtual machine emulation, anti-monitors techniques, anti-memory patching

Along with this, malware authors included various additional modules to track the user’s geolocation and language preferences to narrow down their targets. By having the geolocation tracking functionality attackers particularly targeting the user’s from Spain/Chile.

After the complete infection process, Emotet send the information to C2 server from victims computer includes date/hour of infection, remote IP from victim’s computer, OS version and antivirus name.

Chile, the USA, Germany, and France were the countries with most hits. From a total of 1089 infections, 175 victims were impacted in Chile, 162 in USA, 137 in Germany and 132 in France.

For more details and complete analysis of this malicious campaign see the Technical Analysis here.

Indicators of compromise (IoCs)

Hashes
Batch script:
9008b75ac8bbaacbda0dc47bb7d631f1c791cb346cc6f6a911e7993da0834c09
1e541b14b531bcac70e77a012b0f0f7f
0ca0cd36fb4c9dfeb3e325a01cfb7b75413d1f81
RAR archive:
b5a84e8079dc8558d3960d711d8591500b69cf79e750ecaf88919e398c59383f
1e541b14b531bcac70e77a012b0f0f7f
0ca0cd36fb4c9dfeb3e325a01cfb7b75413d1f81
Malware Payload (EMOTET):
421448d92a6d871b218673025d4e4e121e263262f0cb5cd51e30853e2f8f04d7
98172becba685afdd109ac909e3a1085
cbb0377ec81d8b120382950953d9069424fb100e

Related Read

Emotet Malware Mass Attack Drops Nozelesn Ransomware on Enterprise Endpoint Systems Via Word Documents

Hackers Launching Weaponized Word Document to Push Emotet & Qakbot Malware

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Sitecore Zero-Day Flaw Allows Remote Code Execution

A critical zero-day vulnerability in Sitecore’s enterprise content management system (CMS) has been uncovered,...

Apache Airflow Misconfigurations Leak Login Credentials to Hackers

A recent investigation into misconfigured Apache Airflow instances has uncovered critical vulnerabilities exposing login...

Two Cybercriminals Arrested for ATM Jackpotting Scheme

Federal authorities have unveiled details of a sophisticated cybercrime operation targeting financial institutions across...

Black Basta’s Notorious Tactics and Techniques Exposed in Leaked Intel

A significant leak of internal chat logs from the Black Basta ransomware group has...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Sitecore Zero-Day Flaw Allows Remote Code Execution

A critical zero-day vulnerability in Sitecore’s enterprise content management system (CMS) has been uncovered,...

Apache Airflow Misconfigurations Leak Login Credentials to Hackers

A recent investigation into misconfigured Apache Airflow instances has uncovered critical vulnerabilities exposing login...

Two Cybercriminals Arrested for ATM Jackpotting Scheme

Federal authorities have unveiled details of a sophisticated cybercrime operation targeting financial institutions across...