Emotet Trojan Intelligently Targets Organizations, Impersonates Victims to Improve Attack Success

Stu Sjouwerman | Jan 21, 2020

Businessman selecting a digital padlock with a world map on the background-1According to new insights from Cisco Talos, this banking malware is getting nastier as it moves into the island hopping space via email attacks using social engineering.

The goal of malware used to be to simply infiltrate an organization, infect one or more endpoints, and aid in the work of stealing data, holding it for ransom, etc. But the Emotet trojan – traditionally seen as malware focused on the banking industry – hase apparently spread its wings and is now leveraging victim’s email to perpetuate its reach and potential number of victim organizations.

According to Cisco Talos, Emotet is leveraging spear phishing attacks using social engineering techniques to create specific campaigns that are aimed at jumping organizations to increase their chances of eventually finding an unsuspecting user that unwittingly engages with Emotet’s malicious emails.

This evolution in tactics shows how cybercriminals are building on the foundation of their own successful malware to create new ways of generating “revenue”.

Emotet relies solely on users falling for phishing attacks. So, putting users through Security Awareness Training is an effective way to educate them on how to identify these kinds of attacks, and how to avoid falling for them. With Emotet looking like it’s only getting more sophisticated in its abilities, stopping it before it ever gains a foothold in your organization is imperative. Security Awareness Training is the answer.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.