TA542, also known as Mummy Spider, is a prolific financially motivated cybercrime threat actor best known for developing, operating, and distributing the Emotet malware and botnet. Active since at least 2014, the group has conducted massive international malspam campaigns delivering Emotet at volumes ranging from hundreds of thousands to millions of messages per campaign. Emotet began as a banking trojan targeting banks in German-speaking countries and evolved into a modular malware platform and loader used for credential theft, email harvesting, spam operations, network propagation, and delivery of additional malware for other criminal actors. TA542’s operations are centered on email-based initial access. The actor has repeatedly used malicious Microsoft Word and Excel documents containing VBA or XL4 macros, as well as URLs leading to such documents, and later adapted to alternative attachment formats including XLL files and zipped LNK attachments as defenders and platform vendors reduced macro effectiveness. Campaigns commonly use business-themed lures such as invoices, payments, quotes, and purchase orders, along with localized language and region-appropriate branding. Since 2019, TA542 has been strongly associated with thread hijacking, replying within stolen or compromised email conversations to increase credibility and infection rates. Emotet under TA542 has functioned as both a botnet and a malware delivery service. Documented follow-on payloads have included Qbot, TrickBot, IcedID, Gootkit, Zeus Panda, and Bumblebee-related activity. Reporting has also described Emotet shifting toward a pay-per-install style loader role, with third-party malware delivered instead of Emotet’s original banking functionality. Emotet modules have included spam capabilities, browser and mail-client credential theft, Outlook address-book theft, email-content harvesting, and a network spreader that enumerates network resources and attempts lateral movement, including brute-force attempts and remote service execution. The actor’s tradecraft has also included defense evasion and execution techniques such as abuse of Regsvr32 to launch downloaded DLL payloads, frequent rotation of payload delivery infrastructure, use of compromised websites for staging, and broad localization across regions. TA542 has targeted organizations across North America, Latin America, Europe, Asia, and Australia, with no consistent single-industry focus evident in high-volume campaigns. Japan has been specifically affected by high-volume Emotet campaigns, and the actor has also been observed targeting Germany, the United Kingdom, the United States, Poland, Australia, and other countries. TA542 is widely regarded as one of the most significant eCrime actors of the Emotet era because of its scale, resilience, and role as an enabler for downstream malware and ransomware ecosystems. The group has also been identified in Western government reporting as a Russia-aligned cybercriminal threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with Emotet campaigns that delivered IcedID Lite as a follow-on payload; Proofpoint notes limited visibility into follow-on payload attribution.
TA542 is responsible for distributing Emotet malware via large-scale email campaigns, often using hijacked email threads or invoice-themed lures. They have recently resumed activity after a hiatus, updating their tactics and leveraging additional malware loaders such as IcedID and Bumblebee.
Conducted high-volume email campaigns delivering Emotet and adapted delivery methods amid Microsoft's macro-blocking changes, using VBA/XL4 macro documents and later XLL files and zipped LNK attachments.
A criminal group associated here with phishing-delivered loader activity used to deploy Emotet, grow the Epoch5 botnet, and establish contact with C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.