1
Threat Overview
A new variant of the 'Emotet' malware has been detected, targeting Windows systems with a vulnerability in the 'Windows Print Spooler' service. The attack vector is a phishing email with a malicious attachment. The vulnerability class is a remote code execution (RCE) vulnerability.
2
Key Intelligence Points
1. The Emotet malware uses a vulnerability in the Windows Print Spooler service (CVE-2021-1678) to gain initial access. 2. The malware targets Windows systems with the vulnerability, allowing for RCE and lateral movement. 3. The attack chain involves a phishing email with a malicious attachment, which is then executed to download and install the Emotet malware. 4. Detection opportunities include monitoring for suspicious print job activity and analyzing system logs for signs of RCE activity.
3
MITRE ATT&CK Techniques
T1204.001 User Execution, T1566.001 Spearphishing Attachment
4
Indicators of Compromise (IOCs) / Affected Systems
Emotet malware, Windows Print Spooler service, CVE-2021-1678, phishing email with malicious attachment
5
Mitigation & Detection
Apply the latest patch for the Windows Print Spooler service (KB5004940) and implement a robust email filtering system to block phishing emails.