Microsoft reports variant of banking malware that targets German speakers

Microsoft says the malware is contained in spam messages that purport to contain important information

Microsoft says German speakers are being targeted by a new variant of a powerful type of malware that steals online banking credentials.

The malware, called Emotet, was spotted around last June by security vendors. It is notable for its ability to sniff out credentials sent over encrypted HTTPS connections by tapping into eight network APIs, according to a writeup from Trend Micro from last year.

Microsoft has been observing a new variant, Trojan:Win32/Emotet.C, which was sent out as part of a spam campaign that peaked in November targeting mostly German-speaking users, wrote HeungSoo Kang of Microsoft's Malware Protection Center.

Emotet is distributed through spam messages, which either contain a link to a website hosting the malware or a PDF document icon that is actually the malware.

The spam messages try to gain the attention of potential victims by purporting to be some sort of claim, a phone bill, an invoice from a bank or a message from PayPal.

Spam messages containing Emotet can be tricky to filter because the messages originate from real email accounts, Kang wrote. One technique to stop spam messages is to reject messages that come from bogus accounts by checking if the account really exists.

Emotet comes with a list of banks and services it is designed to steal credentials from. It will also pull credentials from a variety of email programs, including versions of Microsoft's Outlook, Mozilla's Thunderbird and instant messaging programs such as Yahoo Messenger and Windows Live Messenger.

The stolen information is sent back to Emotet's "command and control (C&C) server where it is used by other components to send spam emails to spread the threat," Kang wrote.

Send news tips and comments to Follow me on Twitter: @jeremy_kirk

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags trend microMicrosoftsecuritymalware

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles


GGG Evaluation Team

Kathy Cassidy


First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni


For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell


The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi


The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott


My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?