• Donate
    TheWindowsForum.com needs donations to stay online!
    Love TheWindowsForum.com? Then help keep it alive by sending a donation!

Emotet spam trojan surges back to life after 5 months of silence

WELCOME TO THEWINDOWSFORUM COMMUNITY!

Our community has more than 63,000 registered members, and we'd love to have you as a member. Join us and take part in our unbiased discussions among people of all different backgrounds about Windows OS, Software, Hardware and more.

A new variant?
That depends. In the strictest definition, no. It's the same framework that's used to deliver the payload.
From that point on it's a different macro that sets in motion a different series of downloads and programs but the end result is similar. Why that framework isn't being flagged is I suspect it's pretty generic, it's that first macro being executed that causes all the chaos. Haven't seen an infection of Emot but I would suspect any good A/V would flag the resulting macro or at least be highly suspect.
 

Latest posts

Back