FortiGuard Labs has discovered that Emotet was recently delivered through an archive file that has a file name targeting those interested in the U.S. midterm elections. The archive file is “US midterm elections The six races that could decide the US Senate.zip” that has a link file with the same name, which leads to Emotet.Why is this Significant?This is significant because Emotet is trying to leverage the interest of the U.S. midterm elections for infection. While FortiGuard Labs has not observed the infection vector, the file name “US midterm elections The six races that could decide the US Senate.zip” was likely distributed via emails. “The six races” likely refers to Arizona, Georgia, Michigan, Nevada, Pennsylvania, and Wisconsin where Democrats and Republican are expected to have close race in the elections, which gives better chance that recipients will open the archive contents. Emotets’ modus operandi includes distribution via malicious spam campaigns and thread hijacking of emails.What’s in “US midterm elections The six races that could decide the US Senate.zip”?The zip file contains a link file named “US midterm elections The six races that could decide the US Senate.lnk”. When the link file is executed, it drops a further script in %tmp% that will attempt to cycle through several URLs to download a Emotet DLL.The downloaded Emotet connects to C2 server and will likely deliver additional malware.FortiGuard Labs discovered that the same script is present in other link files “New York Election news and updates….lnk” and “Amazon warns of slower sales as economy weakens.lnk” that were submitted to VirusTotal at the end of October and beginning of November respectively.What is the Status of Protection?FortiGuard Labs provides the following AV signatures for the archive and link file involved in the attack:• LNK/Agent.AMY!tr.dldr• PossibleThreat.PALLAS.HC2 address is blocked by FortiGuard Webfiltering Client.
More Stories
python-uv-build-0.6.14-2.fc43 rust-gitui-0.26.3-6.fc43 rust-gstreamer-0.23.5-2.fc43 rust-ron-0.9.0-1.fc43 rust-version-ranges-0.1.1-2.fc43 rust-zip-2.6.1-1.fc43 uv-0.6.14-3.fc43
FEDORA-2025-1311e4cd58 Packages in this update: python-uv-build-0.6.14-2.fc43 rust-gitui-0.26.3-6.fc43 rust-gstreamer-0.23.5-2.fc43 rust-ron-0.9.0-1.fc43 rust-version-ranges-0.1.1-2.fc43 rust-zip-2.6.1-1.fc43 uv-0.6.14-3.fc43 Update description: Update rust-ron to 0.9. Update rust-zip...
rpki-client-9.5-1.el10_0
FEDORA-EPEL-2025-2ec16b3a94 Packages in this update: rpki-client-9.5-1.el10_0 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc41
FEDORA-2025-17fed14cc3 Packages in this update: rpki-client-9.5-1.fc41 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc40
FEDORA-2025-d5fdbedb7f Packages in this update: rpki-client-9.5-1.fc40 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.el9
FEDORA-EPEL-2025-f8a9a83d41 Packages in this update: rpki-client-9.5-1.el9 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.el10_1
FEDORA-EPEL-2025-f8fbd7b9af Packages in this update: rpki-client-9.5-1.el10_1 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....