Last seven days
- First activity
- Jul 28, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2
- Host form
- 6 IP / 0 hostnames
Emotet is a modular Windows malware family first identified in 2014 that began as a banking trojan and evolved into one of the most prominent malware delivery platforms in cybercrime.
Profile source: Mallory opens in a new tabEmotet
Emotet is a modular Windows malware family first identified in 2014 that began as a banking trojan and evolved into one of the most prominent malware delivery platforms in cybercrime. It is widely associated with large-scale spam operations and has been linked to the threat cluster commonly tracked as TA542 or Mummy Spider. Over time, Emotet shifted from primarily targeting financial data to functioning as a loader and botnet capable of delivering additional malware, including banking trojans, information stealers, ransomware, and other follow-on payloads such as TrickBot.
Emotet is best known for email-borne infection chains that rely on phishing or spearphishing lures themed as invoices, payments, shipping notices, or hijacked email threads. Delivery has historically used malicious Office documents with VBA or Excel 4.0 macros, and later expanded to formats such as XLL add-ins, zipped shortcut attachments, password-protected archives, and HTML smuggling as defenders improved macro-based detection. Typical execution chains use native Windows utilities and scripting engines, including mshta, PowerShell, rundll32, and regsvr32, to retrieve and launch staged payloads.
The malware employs obfuscation and anti-analysis measures including encrypted strings and resources, dynamic API resolution, control-flow obfuscation, runtime decryption, and polymorphic variation. Observed variants use staged execution with an initial dropper and a resident bot component. Persistence can be established through user Run keys or Windows services depending on privilege level. Emotet also stores embedded command-and-control information in its binaries and uses encrypted communications, including RSA- and AES-protected traffic over HTTP POST with randomized request structure.
Operationally, Emotet serves as an initial-access and malware-delivery platform that enables broader compromise. Reported campaigns and intrusion chains show it downloading and executing additional binaries or plugins, supporting post-compromise activity by other tooling, and acting as a precursor to ransomware deployment. It has been observed in enterprise intrusions that progressed to remote access, lateral movement, data exfiltration, and domain-wide ransomware impact. Emotet primarily targets Windows environments and has affected organizations across sectors worldwide through high-volume malicious email campaigns.
C2 tracking
Derp observations, rolling seven-day window
Samples
1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5 b99f64b00c6db22efe021feb7cf7474d643d7704acde69ba6a453205a166d576 c2ba065654f13612ae63bca7f972ea91c6fe97291caeaaa3a28a180fb1912b3a e076c41fad85f9206f5e084125d2f561c00d9b124990054b9e969044e7d056c7 f423492dcdd5464e4653cb11ef97f1e8e2a6cc79e6b3c03cf87ab07a33c44fd4 7bfcf2467e088c97d3c9946f5d07608d0248c30ddfa7218d354ed166483e4d7e Reported operators
An observed attack chain for this technique was provided by NETBYTESEC, detailing an infection flow with Emotet obtaining initial access through the execution of a malicious document...
According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.
SilentBuilder is a campaign that is being used to launch bankers such as Emotet to increase the Epoch5 botnet...
Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.
Le 11 mars 2022, le compte Twitter @Cryptolaemus1 a identifié la distribution d’un implant SystemBC par le botnet Epoch 5 lié au Malware-as-a-Service (MaaS) Emotet.
"...GOLD CRESTWOOD's Emotet botnet..."
"...MUMMY SPIDER’s Emotet was leveraged by MALLARD SPIDER and WIZARD SPIDER."
"...shift away from the malware that had been the basis of most Ryuk attacks last year (Emotet and Trickbot)."
Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.
"The gang is believed to be behind the recent revival of the notorious Emotet botnet, which could lead to a massive new wave of ransomware infections."
The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking industry to steal credentials. However... Emotet has evolved far beyond those beginnings to become what a ThreatPost article called a threat-delivery service.
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.