News

Microsoft discovers banking malware that targets German users

Wednesday 7 January 2015 10:29 CET | News

Microsoft has unveiled that German speakers are being targeted by a new variant of a powerful type of malware that steals online banking credentials.

The malware, dubbed Emotet, was spotted around June 2014 by security vendors. It is notable for its ability to sniff out credentials sent over encrypted HTTPS connections by tapping into eight network APIs.

Microsoft has been observing a new variant, which was sent out as part of a spam campaign that peaked in November targeting mostly German-speaking users. Emotet is distributed through spam messages, which either contain a link to a website hosting the malware or a PDF document icon that is actually the malware.

The spam messages try to gain the attention of potential victims by purporting to be some sort of claim, a phone bill, an invoice from a bank or a message from PayPal.

Spam messages containing Emotet can be tricky to filter because the messages originate from real email accounts.One technique to stop spam messages is to reject messages that come from bogus accounts by checking if the account really exists.

Emotet comes with a list of banks and services it is designed to steal credentials from. It will also pull credentials from a variety of e-mail programs, including versions of Microsoft’s Outlook, Mozilla’s Thunderbird and instant messaging programs such as Yahoo Messenger and Windows Live Messenger.

 


Free Headlines in your E-mail

Every day we send out a free e-mail with the most important headlines of the last 24 hours.

Subscribe now

Keywords: Microsoft, German users, banking malware, online banking, Emotet, online security
Categories: Fraud & Financial Crime
Companies:
Countries: World
This article is part of category

Fraud & Financial Crime






Industry Events