It’s Baaaaaaaack! Emotet Trojan Rears Its Ugly Head Once Again After a 3-Month Vacation

Stu Sjouwerman | Oct 15, 2019

emotet-banking-malwareOne of the most dangerous pieces of malware to-date, this trojan-turned-botnet has come back after a brief hiatus and appears to be a part of a new spear phishing campaign targeting organizations.

Emotet, once considered “among the most costly and destructive malware”, according to the U.S. Cybersecurity and Infrastructure Agency, has come back to life in a new campaign, according to threat researchers at Malwarebytes.

The campaign, aimed at organizations in both the United States and several specific European Union countries, is focused on getting potential victims to open and interact with an email using the subject of “Payment Remittance Advice”.

Recipients are presented with a Word doc attachment and the message “Your statement is attached. Please remit payment at your earliest convenience.”

This is dangerous malware – it’s a sophisticated credential-stealing piece of malware badness that cause organizations to incur massive costs, such as the $1 million price tag for the City of Allentown.

Organizations need to not just put users on alert to be watchful for emails seeking payment remittance, but engage them in ongoing Security Awareness Training as a last line of defense to ensure users understand the need for good security practices and to avoid any kind of suspicious email links and attachments.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.