Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Emotet Malware Wants To Invite You To A Halloween Party

Emotet Malware Wants To Invite You To A Halloween Party

To take advantage of the trick-or-treating festivities, the Emotet malware gang is sending out spam emails that invite you to a Halloween party.

Emotet is a malware infection that spreads through emails containing Word documents containing malicious macros. Once these documents are opened, they will try to trick the user into enabling macros that download the Emotet malware onto the computer.

Once the malware is installed, Emotet will use the computer to send spam emails and ultimately install other malware that could lead to a ransomware attack on the victim’s network.

Emotet is playing a Halloween trick

The Emotet malware gang has created an email that pretends to invite you to a Halloween party to trick you into opening the malicious attachment.

Also Read: How To Send Mass Email Without Showing Addresses: 2 Great Workarounds

Halloween party Emotet email

While the email subjects and text of the Halloween-themed emails vary, the general idea is that you are being invited to a Halloween party, with all the details in the attached malicious document.

An example of the text found in one of these emails is:

Dear, 

If you are coming it would be good!

Details in the attachment.

According to FireEye’s Alex Lanstein, the different names used for the malicious Word attachments in the 2020 Halloween Emotet campaign include:

Inviting friends to your Halloween Extravaganza.doc
Halloween.doc
Halloween party invitation.doc
Halloween Pot Luck 10.31.doc
Halloween party.doc

If a user opens the attachment, they will be greeted with the standard “Enable Editing” and “Enable Content” button, that when clicked, will install the Emotet Trojan on the computer.  So, make sure not to click it!

Malicious document

Like last year, Emotet did not bother updating their template to use a Halloween orange and black color theme or make it festive by including an image of a pumpkin.

Also Read: How A Smart Contract Audit Works And Why It Is Important

Instead, Emotet is sticking with their document template that asks users to upgrade their installed Microsoft Word version.

If you receive an email with an invite to a Halloween party and it tells you to open an attachment, do not open it. Instead, eat some candy as a treat for not falling for their trick.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us