Thursday, February 27, 2025
HomeComputer SecurityHackers Targeted Retailing Industry With Malware and Selling Stolen Data On Dark...

Hackers Targeted Retailing Industry With Malware and Selling Stolen Data On Dark Web

Published on

SIEM as a Service

Follow Us on Google News

Hackers deploy Emotet malware targeting retail trading industry to exfiltrate the bundles of data and to sell them on the dark web.

The Emotet malware is a highly sensitive banking malware which was originally found in 2014, it is capable of stealing financial credentials, usernames, passwords and email addresses.

Panda Trading Systems detected the malware activity in their routine analysis of client machines and the investigation is ongoing.

Flow of Emotet Malware Infection

The infection starts with the crafted phishing email that carries themed invoice or shipment attachments.

If the users open the document that contains the malicious attachment, then the malicious macro downloads the Emotet malware.

Emotet malware
CREDITS : US Department of Homeland Security

To maintain persistence the Emotet malware creates registry autostart keys and then it use to inject itself into the system running process.

Once the registry keys are added, it reports the infection to the command and control server and start receiving instructions from the attackers.

The Emotet malware includes components such as netpass.exe, outlook scraper, web browser pass view, mail pass view, and credential emulator which allows attackers to steal the passwords and financial credentials form browsers and emails.

PandaTS told Finance Magnates that the hackers have managed to infect hundreds of computers belonging to brokers and affiliate marketers. The Finance Magnates reached out to a number of retail brokers to see how widely the malware has spread.

According to Finance magnets, some of the retailers are unaffected and some retailers confirm the hackers has attempted with varying degrees of success, to steal data from them.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

Wannamine Malware Still Penetrate the Unpatched SMB Computers using NSA’s EternalBlue Exploit

New Xbash Malware Attack on Linux & Windows with Botnet, Ransomware & Coinminer Capabilities

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...