Skip to content

Emotet

Emotet is a modular Windows malware family first identified in 2014 that began as a banking trojan and evolved into one of the most prominent malware delivery platforms in cybercrime.

Profile source: Mallory opens in a new tab

Emotet

Family profile

Emotet is a modular Windows malware family first identified in 2014 that began as a banking trojan and evolved into one of the most prominent malware delivery platforms in cybercrime. It is widely associated with large-scale spam operations and has been linked to the threat cluster commonly tracked as TA542 or Mummy Spider. Over time, Emotet shifted from primarily targeting financial data to functioning as a loader and botnet capable of delivering additional malware, including banking trojans, information stealers, ransomware, and other follow-on payloads such as TrickBot.

Emotet is best known for email-borne infection chains that rely on phishing or spearphishing lures themed as invoices, payments, shipping notices, or hijacked email threads. Delivery has historically used malicious Office documents with VBA or Excel 4.0 macros, and later expanded to formats such as XLL add-ins, zipped shortcut attachments, password-protected archives, and HTML smuggling as defenders improved macro-based detection. Typical execution chains use native Windows utilities and scripting engines, including mshta, PowerShell, rundll32, and regsvr32, to retrieve and launch staged payloads.

The malware employs obfuscation and anti-analysis measures including encrypted strings and resources, dynamic API resolution, control-flow obfuscation, runtime decryption, and polymorphic variation. Observed variants use staged execution with an initial dropper and a resident bot component. Persistence can be established through user Run keys or Windows services depending on privilege level. Emotet also stores embedded command-and-control information in its binaries and uses encrypted communications, including RSA- and AES-protected traffic over HTTP POST with randomized request structure.

Operationally, Emotet serves as an initial-access and malware-delivery platform that enables broader compromise. Reported campaigns and intrusion chains show it downloading and executing additional binaries or plugins, supporting post-compromise activity by other tooling, and acting as a precursor to ransomware deployment. It has been observed in enterprise intrusions that progressed to remote access, lateral movement, data exfiltration, and domain-wide ransomware impact. Emotet primarily targets Windows environments and has affected organizations across sectors worldwide through high-volume malicious email campaigns.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 28, 2026
Last activity
Jul 28, 2026
Feed role
C2
Host form
6 IP / 0 hostnames

Leading locations

  • US4
  • AU1
  • FR1

Leading providers

  • DigitalOcean, LLC3
  • Charter Communications Inc1
  • Contabo GmbH1
  • Telstra Limited1

Infrastructure traits

  • Hosting 4
  • Vpn 3

Samples

Recent associated samples

Reported operators

Threat actors

11 named in public reporting
TA551

An observed attack chain for this technique was provided by NETBYTESEC, detailing an infection flow with Emotet obtaining initial access through the execution of a malicious document...

Unsafe

According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.

TA542

SilentBuilder is a campaign that is being used to launch bankers such as Emotet to increase the Epoch5 botnet...

WIZARD SPIDER

Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.

PISTACHE TEMPEST

Le 11 mars 2022, le compte Twitter @Cryptolaemus1 a identifié la distribution d’un implant SystemBC par le botnet Epoch 5 lié au Malware-as-a-Service (MaaS) Emotet.

MALLARD SPIDER

"...MUMMY SPIDER’s Emotet was leveraged by MALLARD SPIDER and WIZARD SPIDER."

Ryuk

"...shift away from the malware that had been the basis of most Ryuk attacks last year (Emotet and Trickbot)."

Storm-0249

Microsoft attributes this campaign to Storm-0249... known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware.

Conti

"The gang is believed to be behind the recent revival of the notorious Emotet botnet, which could lead to a massive new wave of ransomware infections."

Mealybug

The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking industry to steal credentials. However... Emotet has evolved far beyond those beginnings to become what a ThreatPost article called a threat-delivery service.

Exploited software

Vulnerabilities linked to Emotet

2 CVEs

MITRE ATT&CK

Emotet in ATT&CK

91 distinct techniques

Techniques

91 techniques
T1218.011 Rundll32 T1204.002 Malicious File T1218.005 Mshta T1112 Modify Registry T1059.001 PowerShell T1105 Ingress Tool Transfer T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1547.001 Registry Run Keys / Startup Folder T1036 Masquerading T1486 Data Encrypted for Impact T1190 Exploit Public-Facing Application T1027 Obfuscated Files or Information T1564.001 Hidden Files and Directories T1071 Application Layer Protocol T1218.010 Regsvr32 T1059 Command and Scripting Interpreter T1204.001 Malicious Link T1566.002 Spearphishing Link T1137 Office Application Startup T1204 User Execution T1566 Phishing T1027.006 HTML Smuggling T1057 Process Discovery T1134 Access Token Manipulation T1218 System Binary Proxy Execution T1082 System Information Discovery T1543.003 Windows Service T1497.001 System Checks T1071.001 Web Protocols T1021.001 Remote Desktop Protocol T1573 Encrypted Channel T1480.002 Mutual Exclusion T1560 Archive Collected Data T1033 System Owner/User Discovery T1656 Impersonation T1001.003 Protocol or Service Impersonation T1132 Data Encoding T1059.003 Windows Command Shell T1547 Boot or Logon Autostart Execution T1649 Steal or Forge Authentication Certificates T1003 OS Credential Dumping T1041 Exfiltration Over C2 Channel T1001.001 Junk Data T1047 Windows Management Instrumentation T1053.005 Scheduled Task T1539 Steal Web Session Cookie T1555.003 Credentials from Web Browsers T1555 Credentials from Password Stores T1550 Use Alternate Authentication Material T1090.003 Multi-hop Proxy T1140 Deobfuscate/Decode Files or Information T1005 Data from Local System T1078 Valid Accounts T1595 Active Scanning T1568 Dynamic Resolution T1587.001 Malware T1564 Hide Artifacts T1585.002 Email Accounts T1622 Debugger Evasion T1027.013 Encrypted/Encoded File T1210 Exploitation of Remote Services T1027.001 Binary Padding T1573.001 Symmetric Cryptography T1027.002 Software Packing T1135 Network Share Discovery T1584.005 Botnet T1016 System Network Configuration Discovery T1053 Scheduled Task/Job T1114 Email Collection T1055.012 Process Hollowing T1106 Native API T1571 Non-Standard Port T1110.001 Password Guessing T1003.001 LSASS Memory T1132.001 Standard Encoding T1570 Lateral Tool Transfer T1620 Reflective Code Loading T1055.001 Dynamic-link Library Injection T1078.003 Local Accounts T1552.001 Credentials In Files T1027.010 Command Obfuscation T1040 Network Sniffing T1087.003 Email Account T1036.004 Masquerade Task or Service T1114.001 Local Email Collection T1027.009 Embedded Payloads T1016.002 Wi-Fi Discovery T1021.002 SMB/Windows Admin Shares T1134.001 Token Impersonation/Theft T1027.014 Polymorphic Code

Reporting

Research mentioning Emotet

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.