Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 14 IP / 4 hostnames
Emotet is a Windows malware family that emerged in 2014 as a modular banking trojan targeting bank-account information.
Profile source: Mallory opens in a new tabEmotet
Emotet is a Windows malware family that emerged in 2014 as a modular banking trojan targeting bank-account information. It later evolved into a prolific initial-stage implant and malware-delivery platform capable of loading additional malware families, including QakBot, TrickBot, and Ryuk. Emotet has stolen and exfiltrated victims’ email inbox contents, contact lists, and SMTP credentials, enabling highly convincing malicious-email campaigns. Later variants searched mailboxes for unanswered conversations and replied within existing threads to improve phishing effectiveness. Emotet uses command-and-control communications and has employed substantial anti-analysis and code-obfuscation measures, including Heaven’s Gate and custom control-flow flattening. Its 64-bit variants dynamically compute configuration data, cryptographic key material, command-and-control information, and strings at runtime, complicating static analysis and signature-based detection. International law-enforcement actions disrupted Emotet infrastructure in January 2021, but the family has historically remained a major cybercrime threat.
C2 tracking
Derp observations, rolling seven-day window
Samples
2ca46d023677717ed34b28ba1d9a0c7c15771518b490e7beb46282864aa06c55 2d3b179077f5a7aea77c70ef7e4219905c2b50680c514e9d3474825fe49f3ce7 4c187f1019cc423c5ea3ca4a5b4ab66ea6019b8500c9777a2578e19aa69c6d7a 8e24e76a6c2ac7a92f65caed6555c233d47e602c57c567aead0550305ea5013e b00784d96811d72a503d8b4f84d32c3c509322fcfdfaa476637d4d425b51deb9 05dbb515120ec8a6a453c91833eacf432e67ffe89fd650ac704eefc6bf8de290 32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f6c46c325441c6407ee6a7ccbc322ce04d4b499085ed80e1c3a86431d647610d Reported operators
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
Emotet has been delivered by phishing emails containing attachments.
Mealybug is identified by its use of its custom malware, Trojan.Emotet. Once on a computer, Emotet downloads and executes a spreader module that contains a password list that it uses to attempt to brute force access to other machines on the same network.
The Emotet malware is now distributed through malicious Windows App Installer packages that pretend to be Adobe PDF software.
First detected in 2014, Emotet is a modular, polymorphic trojan that is capable of evading signature-based detection and spreading throughout a victim network to compromise additional systems. Emotet often serves as a first–or second–stage malware that can drop and download further payloads...
A good example associated with this group is the use of Emotet.
After five months of inactivity, the prolific and well-known Emotet botnet re-emerged on July 17th. The purpose of this botnet is to steal sensitive information from victims or provide an installation base for additional malware such as TrickBot...
First detected in 2014, Emotet is a modular, polymorphic trojan that is capable of evading signature-based detection and spreading throughout a victim network to compromise additional systems. Emotet often serves as a first–or second–stage malware that can drop and download further payloads...
First identified in 2014 (as the Geodo banking Trojan) ... Emotet appears to be back after four months of inactivity ... Since 2017, however, Emotet is no longer used as a Trojan but as a loader-as-a-service (LaaS) for the purpose of distributing malicious code within the information systems it infects.
Emotet (alias Heodo), apparu en mars 2017, est la quatrième itération du code malveillant Geodo.
First identified in 2014 (as the Geodo banking Trojan) ... Emotet appears to be back after four months of inactivity ... Since 2017, however, Emotet is no longer used as a Trojan but as a loader-as-a-service (LaaS) for the purpose of distributing malicious code within the information systems it infects.
The messages also include individuals representing GOLD CRESTWOOD (Emotet), GOLD MYSTIC (LockBit), and GOLD SWATHMORE (IcedID), who frequently communicate with Stern and other GOLD ULRICK and GOLD BLACKBURN members.
Emotet (alias Heodo), apparu en mars 2017, est la quatrième itération du code malveillant Geodo.
Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
Emotet (aka Heodo) first appeared in March 2017 and is the fourth iteration of the Geodo malware... Since 2017, Emotet is no longer used as a banking trojan horse ... but distributes malwares operated by attackers, customers of TA542, within the information systems it infects.
Emotet is one of the most common malware loaders in the wild. It has been used by the TrickBot gang to install their eponymous banking trojan.
Notably, TrickBot has been widely observed working in conjunction with Emotet to deliver Ryuk ransomware.
An observed attack chain for this technique was provided by NETBYTESEC, detailing an infection flow with Emotet obtaining initial access through the execution of a malicious document...
According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.
Le 11 mars 2022, le compte Twitter @Cryptolaemus1 a identifié la distribution d’un implant SystemBC par le botnet Epoch 5 lié au Malware-as-a-Service (MaaS) Emotet.
"...MUMMY SPIDER’s Emotet was leveraged by MALLARD SPIDER and WIZARD SPIDER."
"...shift away from the malware that had been the basis of most Ryuk attacks last year (Emotet and Trickbot)."
Exploited software
MITRE ATT&CK
Reporting
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.