Friday, February 7, 2025
HomeMalwareHackers Delivering Emotet Malware Via Microsoft Office Documents

Hackers Delivering Emotet Malware Via Microsoft Office Documents

Published on

SIEM as a Service

Follow Us on Google News

A new malware campaign that delivers Emotet Malware Via Microsoft Office documents attachments with “Greeting Card” as the document name.

Attackers targeted the USA’s Independence Day to trick users into downloading the malicious document and to install the malware.

The Banking Trojan EMOTET was identified in 2014, it has the capabilities of stealing personal information such as username and Passwords.

Emotet Malware Campaign

The new malware campaign was spotted by Zscaler’s research team and it is active between July 2nd to July 4th, “We saw over two dozen unique payloads hitting our Cloud Sandbox in the 48-hour span.” said Zscaler.

The document contains a tricky social-engineered message that asks users to enable content that allows the malicious macro to run in the background. The Macro obfuscated to avoid detection’s and it triggers wscript.exe to run the command.

Emotet Malware

Wscript downloads the payload through PowerShell script, finally, the De-obfuscated PowerShell command parameters download the Emotet payload and drops in the temp directory.

Emotet is a widely distributed malware it is commonly distributed via malicious spam campaigns that contain office documents, every time it emerges with new capabilities.

It is a multi-component malware that is capable of stealing credentials through browsers and email, Man-in-the-Browser attack and email harvesting.

With the last campaign, it includes a future called RunPE, that hides malware into the Legitimate process to evade the security scanners and inject its code into windows executable process.

Also Read

Important Security practices for users to Open Microsoft Office Documents Securely

EMOTET Malware Hijacking the Windows API & Evade the Sandbox Analysis

Banking Trojan Called “EMOTET” Re-emerging to Steal Username And Password

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Dell Update Manager Plugin Flaw Exposes Sensitive Data

Dell Technologies has issued a security advisory (DSA-2025-047) to address a vulnerability in the Dell Update...

DeepSeek iOS App Leaks Data to ByteDance Servers Without Encryption

DeepSeek iOS app—a highly popular AI assistant recently crowned as the top iOS app...

Critical Flaws in HPE Aruba ClearPass Expose Systems to Arbitrary Code Execution

Hewlett Packard Enterprise (HPE) has issued a high-priority security bulletin addressing multiple vulnerabilities in...

Splunk Introduces “DECEIVE” an AI-Powered Honeypot to Track Cyber Threats

Splunk has unveiled DECEIVE (DECeption with Evaluative Integrated Validation Engine), an innovative, AI-augmented honeypot that mimics...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Flesh Stealer Malware Attacking Chrome, Firefox, and Edge Users to Steal Passwords

A newly identified malware, Flesh Stealer, is rapidly emerging as a significant cybersecurity threat...

Beware of Nova Stealer Malware Sold for $50 on Hacking Forums

The cybersecurity landscape faces a new challenge with the emergence of Nova Stealer, a...

XE Hacker Group Exploiting Veracode 0-Day’s to Deploy Malware & Steal Credit Card Details

The XE Group, a sophisticated Vietnamese-origin cybercrime organization active since 2013, has escalated its...