Full Report
Microsoft has warned of a new variant of a banking malware that appears to be targeting German speakers, according to PC World.
Analysis Summary
# Threat Actor: Emotet (Variant)
## Attribution & Identity
The threat being discussed is a **new variant of the banking malware Emotet**.
No specific organizational attribution or long-term threat actor group name is provided; the intelligence originates from reports by Microsoft (HeungSoo Kang of Microsoft's Malware Protection Center) and external publications (PC World, IT World).
## Activity Summary
The primary activity reported is a recent spam campaign utilizing a variant of the Emotet banking malware. This campaign appears to be **predominantly targeting German speakers** and aims to compromise banking credentials. The malware spreads via spam email messages impersonating legitimate correspondence like claims, phone bills, invoices from banks, or PayPal messages.
## Tactics, Techniques & Procedures
- **Distribution via Spam:** Spreading through large-scale spam email campaigns.
- **Malicious Payloads:** Emails contain either a link to a malicious website or an attachment disguised as a PDF icon which is the malicious content.
- **Evasion:** Emails are difficult to filter because they originate from real, legitimate email addresses.
- **Credential Harvesting:** Capable of detecting banking credentials over encrypted HTTPS connections by tapping into eight network APIs.
- **Data Exfiltration:** Stolen information (usernames and passwords) is exfiltrated to a Command and Control (C2) server.
- **Self-Propagation:** The malware can use compromised email accounts to spread itself further via additional spam email.
- **Local Credential Theft:** Stealing email account usernames and passwords from installed email or messaging software.
- *No specific MITRE ATT&CK IDs were present in the text.*
## Targeting
- **Sectors:** Banking sector is the direct target via credential theft. General users receiving spam are initially targeted.
- **Geography:** Predominantly targeting **German users** at the time of the report.
- **Victims:** Specific organizations were not named, but targeted software includes: Gmail Notifier, Google Talk, Mozilla Thunderbird, Windows Live Messenger, various versions of Outlook, Windows Live Mail, and Yahoo! Messenger.
## Tools & Infrastructure
- **Malware Families used:** Emotet (new variant).
- **Infrastructure (C2, domains, IPs):** Stolen data is sent back to a Command and Control server (C2). Specific C2 domains or IPs were not provided.
## Implications
This variant of Emotet poses a significant risk to German-speaking users due to its targeted nature and its capability to bypass HTTPS filtering by tapping directly into API-level connections to steal banking credentials. Furthermore, its ability to steal email credentials and use them for further spam distribution indicates a high potential for rapid, large-scale infection propagation.
## Mitigations
- Enhanced scrutiny of emails, especially those appearing to be from banks, PayPal, or invoices/claims, even if they appear to originate from legitimate addresses.
- Monitoring for unusual network activity related to banking credential handling.
- Deploying security solutions capable of detecting malware families like Emotet.
- Monitoring for evidence of systems attempting to extract usernames/passwords from common messaging and email clients.