Emotet Campaign Uses Malicious OneNote Files to Get Around Microsoft Blocks
According to Check Point Software Technologies, a new Emotet campaign is distributing malicious OneNote files by circumventing Microsoft security measures. This was included in the March 2023 Global Threat Index. Last month, researchers discovered a new malware campaign for the Emotet Trojan, which had risen to become the second most common malware. Since Microsoft announced

Emotet Campaign Uses Malicious OneNote Files to Get Around Microsoft Blocks

According to Check Point Software Technologies, a new Emotet campaign is distributing malicious OneNote files by circumventing Microsoft security measures. This was included in the March 2023 Global Threat Index. Last month, researchers discovered a new malware campaign for the Emotet Trojan, which had risen to become the second most common malware.
Since Microsoft announced that it would block macros in office files, emotet attackers have been looking for new ways to distribute malicious files. The attackers used a new strategy in this campaign, sending spam emails containing a malicious OneNote file. When the document is opened, a bogus message appears, tricking the victim into clicking it, which downloads the Emotet infection. When malware is installed, it can collect user email data such as login credentials and contact information. The attackers then use the data gathered to broaden the campaign’s reach and facilitate future attacks.
“While big tech companies do their best to cut off cybercriminals at the source, it’s nearly impossible to prevent every attack from circumventing security measures,” said Maya Horowitz, VP of Research at Check Point Software. Emotet is a sophisticated Trojan, so it’s no surprise that it’s managed to evade Microsoft’s most recent defenses. The most important thing people can do is ensure adequate email security, avoid downloading unexpected files, and maintain a healthy skepticism about the origins and contents of emails.”
The most exploited vulnerability, according to Check Point Research (CPR), was Apache Log4j Remote Code Execution, which affected 44% of organizations globally, followed by HTTP Headers Remote Code Execution, which affected 43% of organizations globally, and MVPower DVR Remote Code Execution, which had a global impact of 40%.
Last month, Qbot was the most prevalent malware family, with a global impact of more than 10%, followed by Emotet and Formbook, each with a 4% global impact.
Qbot, also known as Qakbot, is a banking Trojan that was first identified in 2008. It was designed to steal a user’s banking credentials or keystrokes, and it is commonly distributed via spam emails. To avoid detection and thwart analysis, Qbot employs a number of anti-VM, anti-debugging, and anti-sandbox techniques.
Emotet is a sophisticated, self-replicating, modular Trojan. Emotet was previously used as a banking Trojan, but it is now being used to distribute other malware or malicious campaigns. To avoid detection, it employs a variety of methods for maintaining persistence and evasion techniques. It can also be spread via phishing emails that contain malicious attachments or links.
FormBook is a data stealer that targets Windows operating systems and was first discovered in 2016. It is marketed as “Malware as a Service (MaaS)” in underground hacking forums due to its strong evasion techniques and low price. Formbook collects credentials from various web browsers, collects screenshots, monitors and logs keystrokes, and can download and execute files based on orders from its C&C.
Last month, education/research remained the most targeted industry globally, followed by government/military and then healthcare.
In terms of mobile malware, Ahmyth has surpassed Anubis and Hiddad to become the most common.
Ahmyth is a remote access Trojan (RAT) that was first discovered in 2017. It is distributed via Android apps, which are available on app stores and various websites. When a user installs one of these infected apps, the malware is able to collect sensitive information from the device and perform actions such as keylogging, screenshots, SMS messages, and camera activation.
Anubis is a banking Trojan malware that targets Android devices. Since its detection, it has gained new capabilities, including Remote Access Trojan (RAT) functionality.



