Skip to content

Emotet

Emotet is a Windows malware family that emerged in 2014 as a modular banking trojan targeting bank-account information.

Profile source: Mallory opens in a new tab

Emotet

Family profile

Emotet is a Windows malware family that emerged in 2014 as a modular banking trojan targeting bank-account information. It later evolved into a prolific initial-stage implant and malware-delivery platform capable of loading additional malware families, including QakBot, TrickBot, and Ryuk. Emotet has stolen and exfiltrated victims’ email inbox contents, contact lists, and SMTP credentials, enabling highly convincing malicious-email campaigns. Later variants searched mailboxes for unanswered conversations and replied within existing threads to improve phishing effectiveness. Emotet uses command-and-control communications and has employed substantial anti-analysis and code-obfuscation measures, including Heaven’s Gate and custom control-flow flattening. Its 64-bit variants dynamically compute configuration data, cryptographic key material, command-and-control information, and strings at runtime, complicating static analysis and signature-based detection. International law-enforcement actions disrupted Emotet infrastructure in January 2021, but the family has historically remained a major cybercrime threat.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 11, 2026
Feed role
C2 / Distribution
Host form
14 IP / 4 hostnames

Leading locations

  • US6
  • DE4
  • CN2
  • NL2
  • FR1
  • JP1
  • KR1
  • TH1

Leading providers

  • FEMO IT SOLUTIONS LIMITED3
  • Amazon.com, Inc.2
  • Cloudflare, Inc.2
  • Omegatech LTD2
  • Amazon.com, Inc.1
  • Bouygues Telecom SA1

Infrastructure traits

  • Hosting 13
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

26 named in public reporting
APT28

In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.

Lazarus

In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.

menuPass

In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.

Conti

The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.

INDRIK SPIDER

The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.

WIZARD SPIDER

Emotet has been delivered by phishing emails containing attachments.

Mealybug

Mealybug is identified by its use of its custom malware, Trojan.Emotet. Once on a computer, Emotet downloads and executes a spreader module that contains a password list that it uses to attempt to brute force access to other machines on the same network.

Cryptolaemus

The Emotet malware is now distributed through malicious Windows App Installer packages that pretend to be Adobe PDF software.

TA542

First detected in 2014, Emotet is a modular, polymorphic trojan that is capable of evading signature-based detection and spreading throughout a victim network to compromise additional systems. Emotet often serves as a first–or second–stage malware that can drop and download further payloads...

The Conti Group

A good example associated with this group is the use of Emotet.

Emotet

After five months of inactivity, the prolific and well-known Emotet botnet re-emerged on July 17th. The purpose of this botnet is to steal sensitive information from victims or provide an installation base for additional malware such as TrickBot...

TA54

First detected in 2014, Emotet is a modular, polymorphic trojan that is capable of evading signature-based detection and spreading throughout a victim network to compromise additional systems. Emotet often serves as a first–or second–stage malware that can drop and download further payloads...

TA545

First identified in 2014 (as the Geodo banking Trojan) ... Emotet appears to be back after four months of inactivity ... Since 2017, however, Emotet is no longer used as a Trojan but as a loader-as-a-service (LaaS) for the purpose of distributing malicious code within the information systems it infects.

DOPPEL SPIDER

Emotet (alias Heodo), apparu en mars 2017, est la quatrième itération du code malveillant Geodo.

Trickbot

First identified in 2014 (as the Geodo banking Trojan) ... Emotet appears to be back after four months of inactivity ... Since 2017, however, Emotet is no longer used as a Trojan but as a loader-as-a-service (LaaS) for the purpose of distributing malicious code within the information systems it infects.

GOLD CRESTWOOD

The messages also include individuals representing GOLD CRESTWOOD (Emotet), GOLD MYSTIC (LockBit), and GOLD SWATHMORE (IcedID), who frequently communicate with Stern and other GOLD ULRICK and GOLD BLACKBURN members.

TA511

Emotet (alias Heodo), apparu en mars 2017, est la quatrième itération du code malveillant Geodo.

Storm-0249

Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

Lunar Spider

Emotet (aka Heodo) first appeared in March 2017 and is the fourth iteration of the Geodo malware... Since 2017, Emotet is no longer used as a banking trojan horse ... but distributes malwares operated by attackers, customers of TA542, within the information systems it infects.

TA505

Emotet is one of the most common malware loaders in the wild. It has been used by the TrickBot gang to install their eponymous banking trojan.

Overdose

Notably, TrickBot has been widely observed working in conjunction with Emotet to deliver Ryuk ransomware.

TA551

An observed attack chain for this technique was provided by NETBYTESEC, detailing an infection flow with Emotet obtaining initial access through the execution of a malicious document...

Unsafe

According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.

PISTACHE TEMPEST

Le 11 mars 2022, le compte Twitter @Cryptolaemus1 a identifié la distribution d’un implant SystemBC par le botnet Epoch 5 lié au Malware-as-a-Service (MaaS) Emotet.

MALLARD SPIDER

"...MUMMY SPIDER’s Emotet was leveraged by MALLARD SPIDER and WIZARD SPIDER."

Ryuk

"...shift away from the malware that had been the basis of most Ryuk attacks last year (Emotet and Trickbot)."

Exploited software

Vulnerabilities linked to Emotet

4 CVEs

MITRE ATT&CK

Emotet in ATT&CK

103 distinct techniques

Techniques

103 techniques
T1114 Email Collection T1566 Phishing T1082 System Information Discovery T1027.009 Embedded Payloads T1071 Application Layer Protocol T1071.001 Web Protocols T1105 Ingress Tool Transfer T1027 Obfuscated Files or Information T1573 Encrypted Channel T1041 Exfiltration Over C2 Channel T1587.001 Malware T1204.002 Malicious File T1059.005 Visual Basic T1070 Indicator Removal T1547.001 Registry Run Keys / Startup Folder T1570 Lateral Tool Transfer T1059.001 PowerShell T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link T1204 User Execution T1021 Remote Services T1036 Masquerading T1021.002 SMB/Windows Admin Shares T1543.003 Windows Service T1027.010 Command Obfuscation T1059.007 JavaScript T1569.002 Service Execution T1560 Archive Collected Data T1518 Software Discovery T1497 Virtualization/Sandbox Evasion T1057 Process Discovery T1528 Steal Application Access Token T1059.003 Windows Command Shell T1059 Command and Scripting Interpreter T1555 Credentials from Password Stores T1055.012 Process Hollowing T1110 Brute Force T1090.003 Multi-hop Proxy T1584 Compromise Infrastructure T1498 Network Denial of Service T1218.010 Regsvr32 T1056.003 Web Portal Capture T1027.002 Software Packing T1053.005 Scheduled Task T1555.003 Credentials from Web Browsers T1003 OS Credential Dumping T1033 System Owner/User Discovery T1106 Native API T1003.001 LSASS Memory T1210 Exploitation of Remote Services T1047 Windows Management Instrumentation T1040 Network Sniffing T1110.001 Password Guessing T1114.001 Local Email Collection T1087.003 Email Account T1134.001 Token Impersonation/Theft T1497.001 System Checks T1555.001 Keychain T1490 Inhibit System Recovery T1566.003 Spearphishing via Service T1218.011 Rundll32 T1027.007 Dynamic API Resolution T1135 Network Share Discovery T1055 Process Injection T1027.013 Encrypted/Encoded File T1571 Non-Standard Port T1027.001 Binary Padding T1140 Deobfuscate/Decode Files or Information T1090.001 Internal Proxy T1204.001 Malicious Link T1055.001 Dynamic-link Library Injection T1016.002 Wi-Fi Discovery T1132.001 Standard Encoding T1573.001 Symmetric Cryptography T1620 Reflective Code Loading T1078.003 Local Accounts T1552.001 Credentials In Files T1036.004 Masquerade Task or Service T1562.004 Disable or Modify System Firewall T1218.007 Msiexec T1220 XSL Script Processing T1595 Active Scanning T1573.002 Asymmetric Cryptography T1588.003 Code Signing Certificates T1027.005 Indicator Removal from Tools T1572 Protocol Tunneling T1218.005 Mshta T1095 Non-Application Layer Protocol T1078 Valid Accounts T1071.004 DNS T1012 Query Registry T1586 Compromise Accounts T1218 System Binary Proxy Execution T1133 External Remote Services T1056.001 Keylogging T1555.005 Password Managers T1018 Remote System Discovery T1592.004 Client Configurations T1203 Exploitation for Client Execution T1112 Modify Registry T1129 Shared Modules T1588.002 Tool T1583 Acquire Infrastructure

Reporting

Research mentioning Emotet

Aug 20
Splunk Research

Detection: Windows Phantom DLL Created on Disk | Splunk Security Content

NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

Aug 19
Splunk Research

Detection: Windows Defender MpClient.dll Loaded by Non-Defender Process | Splunk Security Content

Aug 19
Splunk Research

Detection: Windows Alternate Data Stream Created Over Local Share | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Defender Threat Detected on Kernel Object Path | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Error Report Created in ReportQueue Manually | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Wermgr Spawning System Integrity Process | Splunk Security Content

Aug 17
Splunk Research

Shieldbreak | Splunk Security Content

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.