{"id":1787,"date":"2022-02-03T12:56:48","date_gmt":"2022-02-03T17:56:48","guid":{"rendered":"https:\/\/ardent-security.com\/?p=1787"},"modified":"2022-02-03T12:56:48","modified_gmt":"2022-02-03T17:56:48","slug":"emotet-ryuk-ransomware-the-stuff-of-nightmares","status":"publish","type":"post","link":"https:\/\/ardent-security.com\/en\/emotet-ryuk-ransomware-the-stuff-of-nightmares\/","title":{"rendered":"Emotet, Ryuk, Ransomware &#8211; The stuff of nightmares"},"content":{"rendered":"<h2>Emotet, Ryuk, Ransomware &#8211; The Stuff of Nightmares<\/h2>\n<p><em>It\u2019s going to be one of those days. Your CISO or head of IT looks worried and you\u2019re getting a familiar burning sensation in your stomach as he explains the situation. He\u2019s getting too technical &#8211; talking about \u201cEmotet\u201d, \u201cMealybug\u201d, and something called \u201cthe infamous Ryuk gang\u201d. You ask the question: \u201cWhat can we do?\u201d You mentally translate his answer into lost revenue and productivity. And an unpleasant conversation with your boss&#8230; <\/em><\/p>\n<p>If your business connects in any way to the internet you are vulnerable to a nasty bit of malware called \u201cEmotet\u201d. This malware first appeared in 2014, the product of the hacker group \u201cMealybug\u201d. It hides in spam emails that appear to originate from trusted vendors like PayPal or DHL. If the user opens the email and attached Word or Excel document (sometimes labeled as an \u201cInvoice\u201d or \u201creceipt\u201d) and the user\u2019s system is connected to the internet, the embedded macro downloads additional code which harvests the machine\u2019s address book and initiates a new batch of spam emails to all the user\u2019s contacts, spreading the infection farther.<\/p>\n<p>But that was just in <em>Mealybug\u2019s <\/em>first generation of Emotet. After seven years the <em>Mealybug<\/em> group now runs a full-service criminal operation providing its malware as a service (MaaS) to other criminal organizations, including the aforementioned <em>Ryuk<\/em> gang, famous for their ransomware attacks on governments, academia, healthcare, manufacturing and technology companies\u2019 digital systems. By 2017, Emotet was also being used to distribute the <em>Trickbot Trojan<\/em> that targeted US banking companies with bogus emails supposedly from a legitimate DropBox mailbox that lured the user to download a \u201csecure document\u201d containing various malware.<\/p>\n<p>How expensive were these attacks? According to the alert sent in July 2018 by <a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/TA18-201A\">the U.S. Dept. of Homeland Security these EMOTET<\/a> infections have cost the infected governmental organizations up to $1 million per incident to resolve.<\/p>\n<p>Your IT folks assured you that your antivirus network guardian programs were fully up-to-date. How did this malware evade detection?<\/p>\n<p>Emotet is polymorphic code. It modifies itself as it self-installs on a machine so that no two versions of the malware look the same after installation. Signature-based antivirus software looks for specific chunks of code (akin to fingerprints), but the Emotet code looks different on every new machine.<\/p>\n<p>There is some good news. The website <em>Bleepingcomputer.com <\/em>reports that in January 2021 international law enforcement isolated and captured the hundreds of distributed cloud-based servers around the globe that were being used to support Emotet\u2019s functions. According to Europol, by April 25, 2021, the\u00a0 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-botnet-disrupted-after-global-takedown-operation\/\">Emotet malware was finally uninstalled from all infected devices<\/a> using a module developed by the German Bundeskriminalamt (BKA) federal police agency.<\/p>\n<p>Unfortunately, the shutdown of Emotet\u2019s infrastructure was temporary. The malware reappeared four months later and as recently as December 15, 2021, the Cryptolaemus Emotet group reported (on <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/emotet-starts-dropping-cobalt-strike-again-for-faster-attacks\/\">BleepingComputer.com<\/a>) that they were \u201c\u2026<em>observing<\/em> <a href=\"https:\/\/www.cobaltstrike.com\/\"><em>Cobalt Strike<\/em><\/a><em> (CS) Beacons being dropped as of the last few minutes\u2026\u201d<\/em>. Those CS modules were being directly downloaded by Emotet from its C2 (Command and Control) server for execution on the infected devices. They quickly spread laterally across the infected endpoints, steal files, and deploy malware with immediate access to the compromised networks.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Bye-bye botnets\ud83d\udc4b Huge global operation brings down the world&#8217;s most dangerous malware.<\/p>\n<p>Investigators have taken control of the Emotet botnet, the most resilient malware in the wild.<\/p>\n<p>Get the full story: <a href=\"https:\/\/t.co\/NMrBqmhMIf\">https:\/\/t.co\/NMrBqmhMIf<\/a> <a href=\"https:\/\/t.co\/K28A6ixxuM\">pic.twitter.com\/K28A6ixxuM<\/a><\/p>\n<p>\u2014 Europol (@Europol) <a href=\"https:\/\/twitter.com\/Europol\/status\/1354398832759599104?ref_src=twsrc%5Etfw\">January 27, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>On January 27<sup>th<\/sup>, <a href=\"https:\/\/www.bbc.com\/news\/technology-55826258\">Europol announced<\/a> that they had apprehended the Ryuk group and taken down their notorious Emotet botnet. However, <u>it is only a question of time<\/u> before other cybercriminal groups fill this vacuum and start targeting more organizations.<\/p>\n<p><strong><em>You\u2019d really like to avoid this outcome for your business. So, what\u2019s to be done?<\/em><\/strong><\/p>\n<p>Today\u2019s interconnected world requires a multi-pronged defense. Antivirus software is no longer sufficient. <a href=\"https:\/\/ardent-security.com\/en\/\"><strong>Ardent Security<\/strong><\/a> offers over a decade of experience helping small to large growth companies around the world proactively respond to new cyber threats. Ardent Security services include:<\/p>\n<p><a href=\"https:\/\/ardent-security.com\/en\/vulnerability-assessment\/\">Vulnerability Assessment (VA)<\/a>: Where is the gap in the walls of your network fortress? Is your network like France\u2019s Maginot Line \u2013 believed impregnable until the Germans slipped past it through Belgium? Quickly identify known flaws in your network.<\/p>\n<p><a href=\"https:\/\/ardent-security.com\/en\/penetration-testing\/\">Penetration Testing:<\/a> In case of a system compromise, what can the attackers do? Adopt an assumed breach zero trust approach and have our experts test your internal network, cloud-based, mobile and web applications to know if you are secure!<\/p>\n<p><a href=\"https:\/\/ardent-security.com\/en\/adversarial-simulation\/\">Adversarial Simulation (AS)<\/a>: Like training a boxer, you need someone testing your defenses and responses; throwing punches and evading your best shots. Practice makes you better. Is your detection and response team efficient? We will find out together.<\/p>\n<p><a href=\"https:\/\/ardent-security.com\/en\/cyber-security-training\/\">Cyber Security Training<\/a>: Training the weakest link in the system \u2013 the human. Forewarned is fore-armed.<\/p>\n<p><a href=\"https:\/\/ardent-security.com\/en\/compliance-resilience-planning\/\">Compliance &amp; Resilience planning<\/a>: Specific analysis and guidance on meeting industry requirements and standards to ensure a more reliable and resilient network.<\/p>\n<p>For help avoiding that dreaded conversation with your VP of Cyber Security in which he sadly informs you of the latest data breach or ransomware attack against your company, contact <a href=\"https:\/\/ardent-security.com\/en\/\"><strong>Ardent Security<\/strong><\/a> today at:<\/p>\n<p style=\"text-align: center;\"><strong>647-478-2600<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>We can help.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Emotet, Ryuk, Ransomware &#8211; The Stuff of Nightmares It\u2019s going to be one of those days. Your CISO or head of IT looks worried and you\u2019re getting a familiar burning sensation in your stomach as he explains the situation. He\u2019s getting too technical &#8211; talking about \u201cEmotet\u201d, \u201cMealybug\u201d, and something called \u201cthe infamous Ryuk gang\u201d. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1788,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[5,6,8],"tags":[21,19,20],"class_list":["post-1787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-article","category-cybersecurity","category-english","tag-canada-pentesting-hacking","tag-cybersecurity-penetrationtesting-toronto","tag-ontario"],"rttpg_featured_image_url":{"full":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"landscape":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"portraits":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"thumbnail":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-150x150.jpg",150,150,true],"medium":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-300x169.jpg",300,169,true],"large":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-1024x576.jpg",1024,576,true],"tf-client-image-size":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-120x120.jpg",120,120,true],"1536x1536":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"2048x2048":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"trp-custom-language-flag":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-16x9.jpg",16,9,true],"et-pb-post-main-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-1080x675.jpg",1080,675,true],"et-pb-portfolio-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-1080x607.jpg",1080,607,true],"et-pb-gallery-module-image-portrait":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet.jpg",1366,768,false],"et-pb-image--responsive--desktop":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-1280x720.jpg",1280,720,true],"et-pb-image--responsive--tablet":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-980x551.jpg",980,551,true],"et-pb-image--responsive--phone":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/02\/Emotet_Ryuk_Ardent_Security_TrojanHorse_Botnet-480x270.jpg",480,270,true]},"rttpg_author":{"display_name":"Ardent Security","author_link":"https:\/\/ardent-security.com\/en\/author\/ardentsecurity\/"},"rttpg_comment":34,"rttpg_category":"<a href=\"https:\/\/ardent-security.com\/en\/category\/article\/\" rel=\"category tag\">article<\/a> <a href=\"https:\/\/ardent-security.com\/en\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ardent-security.com\/en\/category\/english\/\" rel=\"category tag\">English<\/a>","rttpg_excerpt":"Emotet, Ryuk, Ransomware &#8211; The Stuff of Nightmares It\u2019s going to be one of those days. Your CISO or head of IT looks worried and you\u2019re getting a familiar burning sensation in your stomach as he explains the situation. He\u2019s getting too technical &#8211; talking about \u201cEmotet\u201d, \u201cMealybug\u201d, and something called \u201cthe infamous Ryuk gang\u201d.&hellip;","_links":{"self":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts\/1787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/comments?post=1787"}],"version-history":[{"count":0,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts\/1787\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/media\/1788"}],"wp:attachment":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/media?parent=1787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/categories?post=1787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/tags?post=1787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}