Emotet 봇넷은 활동을 재개

일시 정지 후, Emotet 봇넷의 관리 서버는 활동을 재개.

아르 자형에서 esearchers Cofense Labs were the first to discover a resurgence of the botnet infrastructure.

는 "Emotet 봇넷은 어제 무덤에서 일어나 새로운 바이너리를 제공하기 시작했다. 우리는 C2 서버 8 월에 동부 표준시 오후 3시 주위 요청을 게시 할 수 응답을 제공하기 시작했다 것으로 나타났습니다 21. Stay vigilant and keep an eye out for any updates as we monitor for any changes”, – wrote Cofense Labs specialists.

또한, 연구원 Black Lotus have published a list of active servers.

Emotet was previously known as a banking trojan, but then changed course and turned into a botnet, distributing various types of ransomware.

Emotet is now one of the most dangerous threats in the world. The network is used to distribute the Trickbot banking Trojan and Ryuk 랜섬. This combination of malware was called the “triple threat” and was used as part of attacks on state administrations in the United States in July 2019.

또한 읽기: Global Threat Index claimed, that Emotet botnet suspended its activities

Researchers noticed that Emotet operators took a break at the beginning of June and correctly assumed that it would not be for long. No new campaigns were observed since then, and the consensus in the infosec community was that the servers were down for maintenance.

전문가에 따르면, the servers have just resumed their activity and there have not made any attempts to spread malware. It is assumed that operators need time to restore systems and prepare a new malicious campaign. Security researcher Benkøw provides a tweet-size list of the stages necessary for respawning the malicious activity.

“They reuse the old IPs so they need time to:
Grab old/new bots
remove ALL the AV bots from today on the panel lol
Run some tests for bypassing anti spam product
Prepare the campaign for the next Clients
etc it takes time”, — wrote Benkøw.

The servers are located in various countries, including Brazil, Mexico, Argentina, 독일, Japan and the USA.

Given the intense activity, experts expect a new malicious campaign in the near future. 그들에 따르면, the attackers will adhere to the old ransomware distribution scheme.

폴리나 리소프스카야

저는 몇 년 동안 마케팅 관리자로 일하고 있으며 흥미로운 주제를 찾는 것을 좋아합니다.

회신을 남겨주

맨 위로 돌아가기 버튼