{"id":39630,"date":"2020-07-31T19:18:10","date_gmt":"2020-07-31T11:18:10","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=39630"},"modified":"2020-07-31T19:23:11","modified_gmt":"2020-07-31T11:23:11","slug":"emotets-return-is-the-canary-in-the-coal-mine-sophos","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2020\/07\/31\/emotets-return-is-the-canary-in-the-coal-mine-sophos\/","title":{"rendered":"Emotet\u2019s return is the canary in the coal mine &#8211; Sophos"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos, a global player in next-generation cybersecurity, discovered that Emotet, the ubiquitous botnet that arrives in the guise of any of a thousand different bogus email messages, never really went away when it suddenly stopped appearing in internal records and feeds of spam emails in February.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sudden disappearance of the malware gave rise to a lot of rumors that the creators had been arrested, or contracted COVID-19, or simply had retired and planned to live the good life on the Black Sea coast. But these theories were squashed on July 17th, when Sophos saw a new wave of Emotet attacks swing back into action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe\u2019ve talked a lot about Emotet in the past, including showing its malware ecosystem, and providing a series of deep-dive 101s, not forgetting showing the authors venting their frustration at Sophos. But then in February 2020, Emotet ceased production \u2013 its botnets stopped activity, and the waves of spam campaigns went silent. This isn\u2019t the first time it\u2019s vanished off the radar, only to rise again months later \u2013 and that\u2019s exactly what we saw again last Friday,\u201d said Richard Cohen, Senior threat researcher and manager of the Abingdon, UK detection team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, Emotet is not merely a tool for thievery, but the botnet acts as a delivery mechanism for other malware, walking it through the firewall over the encrypted channels it creates, bypassing network-based defenses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, Sophos investigated many cases in which a large-scale ransomware infection began as the result of this simple but effective Trojan lying undetected for a period of time, before the infected computer was used as a staging area for a larger attack against the company or organization on whose network it insinuated itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Emotet gang has not changed their same, fundamental playbook they\u2019ve followed for years. If you receive an email from an unknown source, or unexpectedly from a known source, with a Microsoft Office file attached, be extremely careful about opening it. In a related vein, if you receive an email that tells you to download such a file attachment in order to receive some sort of invoice or statement, be extremely suspicious.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The sudden disappearance of the malware gave rise to a lot of rumors that the creators had been arrested, or contracted COVID-19, or simply had retired and planned to live the good life on the Black Sea coast. But these theories were squashed on July 17th, when Sophos saw a new wave of Emotet attacks swing back into action.<\/p>\n","protected":false},"author":6,"featured_media":35630,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[54,2103,3914,53,4100,4234,206,4328],"class_list":["post-39630","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-security","tag-security-breach","tag-security-platform","tag-security-risk-management","tag-security-solutions","tag-security-as-a-service","tag-sophos","tag-sophoslabs"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/39630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=39630"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/39630\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/35630"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=39630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=39630"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=39630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}