Menu
Microsoft reports variant of banking malware that targets German speakers

Microsoft reports variant of banking malware that targets German speakers

Microsoft says the malware is contained in spam messages that purport to contain important information

Microsoft says German speakers are being targeted by a new variant of a powerful type of malware that steals online banking credentials.

The malware, called Emotet, was spotted around last June by security vendors. It is notable for its ability to sniff out credentials sent over encrypted HTTPS connections by tapping into eight network APIs, according to a writeup from Trend Micro from last year.

Microsoft has been observing a new variant, Trojan:Win32/Emotet.C, which was sent out as part of a spam campaign that peaked in November targeting mostly German-speaking users, wrote HeungSoo Kang of Microsoft's Malware Protection Center.

Emotet is distributed through spam messages, which either contain a link to a website hosting the malware or a PDF document icon that is actually the malware.

The spam messages try to gain the attention of potential victims by purporting to be some sort of claim, a phone bill, an invoice from a bank or a message from PayPal.

Spam messages containing Emotet can be tricky to filter because the messages originate from real email accounts, Kang wrote. One technique to stop spam messages is to reject messages that come from bogus accounts by checking if the account really exists.

Emotet comes with a list of banks and services it is designed to steal credentials from. It will also pull credentials from a variety of email programs, including versions of Microsoft's Outlook, Mozilla's Thunderbird and instant messaging programs such as Yahoo Messenger and Windows Live Messenger.

The stolen information is sent back to Emotet's "command and control (C&C) server where it is used by other components to send spam emails to spread the threat," Kang wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags trend microMicrosoftsecuritymalware

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments