Emotet Evolving with New Attack and Evasion Techniques

Keeping Endpoint Detection and Response (EDR) systems up-to-date and properly tuned can help companies identify process injection attacks. To help prevent the macro bypass, companies should limit write access to the default Templates directories for Microsoft Office. The SMB spreader can be detected by collecting a baseline of standard SMB netflow traffic and alerting against deviations from that, though this requires a well-staffed security team.

https://thehackernews.com/2023/01/emotet-malware-makes-comeback-with-new.html