{"id":25979,"date":"2020-08-11T11:13:30","date_gmt":"2020-08-11T11:13:30","guid":{"rendered":"https:\/\/www.retarus.com\/blog\/emotet-returns-to-cause-even-greater-harm\/"},"modified":"2026-08-11T12:51:10","modified_gmt":"2026-08-11T12:51:10","slug":"emotet-returns-to-cause-even-greater-harm","status":"publish","type":"post","link":"https:\/\/www.retarus.com\/blog\/en\/emotet-returns-to-cause-even-greater-harm\/","title":{"rendered":"Emotet returns to cause even greater harm"},"content":{"rendered":"\n
After a break in transmission of roughly half a year, the devious trojan known as Emotet is now active again and flooding the inboxes of companies and authorities with deceptively genuine looking emails which are also highly dangerous.<\/p>\n\n\n\n
Since the end of July, the experts at the Retarus Threat Intelligence unit have been registering an almost constant barrage of Emotet attacks. The treacherous thing about Emotet emails is that they at first glance appear to have been sent by a real colleague, make reference to previous email conversations, and recently even started adding documents from earlier conversations<\/a> as attachments. Creating this illusion of familiarity lowers the threshold for the recipient to click on the link included in the text \u2013 with disastrous consequences.<\/p>\n\n\n\n Emotet<\/a> mostly uses MS Word documents contaminated with macro viruses to infect IT systems. The creators of the malware, and those looking to profit from it, store the malware on a constantly alternating<\/a> series of unsuspicious looking servers. When someone has been fooled into opening one of these files and activating the macros it contains, the malware reads the address book and emails from Microsoft Outlook (also known as \u201cOutlook harvesting\u201d) and uses the information to generate more malicious emails to recipients in the network under attack. Emotet is moreover able to download further malware, for instance to snatch login credentials or gain remote access. The general aim of the malware is to paralyze the company\u2019s entire IT network and\/or to blackmail the victim to make ransom payments.<\/p>\n\n\n\n There is no safeguard that can provide you with 100% protection from Emotet, in no small part because the polymorphous malware, first discovered in 2014, keeps changing and evolving due to constant development. A powerful email security service combined with the appropriate sensitization of users, however, goes a long way towards repelling the malware in many cases, and in case infection occurs, contain it and limit the impact.<\/p>\n\n\n\n It is worth noting that Retarus\u2019 portfolio of services includes the groundbreaking post-delivery protection service Patient Zero Detection<\/a>\u00ae, which has been patented in all relevant markets. This service makes it possible to detect malware and harmful hyperlinks in emails which have already been delivered as soon as the corresponding patterns have become available for one of the four scanners deployed in Retarus\u2019 AntiVirus MultiScan, allowing the service to alert recipients as well as administrators about the danger.<\/p>\n\n\n\nHow can you protect yourself from Emotet?<\/h2>\n\n\n\n
