Posted on November 11, 2019, by Vedran Bozicevic | 1 minute read
Despite a nearly four-month absence, the return of Emotet within the last two weeks of September accounted for nearly 12 percent of all malicious email samples in Q3, delivering millions of messages with malicious URLs or attachments, Proofpoint found.
TA542, the cybercriminal group responsible for distributing Emotet, also expanded its regional targeting during this period to several new countries, including Italy, Spain, Japan, Hong Kong, and Singapore.
Reverting to methods that the group had shifted away from in early 2019, TA542’s re-emergence included highly targeted seasonal and topically relevant lures rather than generic financial themes. For example, on Sept. 23, Proofpoint observed the actor leveraging news-related “Snowden” lures.

Read more: Help Net Security
Request a Free Consultation with our Specialists
Contact Now