TA542, also known as Mummy Spider, is a prolific cybercrime threat actor tracked by Proofpoint since 2014 and widely associated with creating, distributing, and operating the Emotet (aka Geodo) botnet. The group has conducted widespread, high-volume international email campaigns, often sending hundreds of thousands to millions of messages, targeting organizations across North America, Latin America, Europe, Asia, Australia, and specifically countries including Japan, Germany, the United Kingdom, the United States, Canada, Austria, Switzerland, and Poland. TA542 primarily distributes Emotet through malspam using social engineering themes such as invoices, payments, quotes, purchase orders, COVID-19, and other business-relevant lures. Reported delivery methods include Microsoft Word and Excel documents containing VBA or XL4 macros, PDFs linking to macro-enabled Word documents, URLs hosted on compromised sites including WordPress installations, and later additional methods such as XLL files and zipped LNK attachments. The actor is noted for language localization, brand impersonation, and, since early April 2019, consistent use of thread hijacking by replying to existing benign email conversations. Emotet, as operated by TA542, evolved from a banking Trojan into a modular malware platform and botnet used for spam distribution, credential theft, email harvesting, and network spreading. Reported modules and capabilities include a spam plugin, credential theft from browsers and mail clients, Outlook/address book harvesting, an email-harvesting module, and a network spreader introduced in 2017 that enumerates network resources and attempts lateral movement. Emotet has also been used as a loader for third-party malware. Content directly associates TA542/Emotet with delivery of Qbot, TrickBot, IcedID, Gootkit, Zeus Panda, and Bumblebee, and notes that in November 2022 Proofpoint observed IcedID Lite as a follow-on payload in a TA542 Emotet campaign. The content also describes TA542 as one of the most prolific email threat actors in recent years due to massive Emotet campaigns. After a break in 2020, the actor resumed operations in July 2020 with relatively limited tactical changes, continuing heavy use of thread hijacking and localized lures. A notable change reported at that time was Emotet primarily delivering Qbot instead of TrickBot. The actor has also been cited in government and industry reporting as a Russian-aligned cybercrime group, and Mummy Spider is explicitly identified as the gang that developed and operates the Emotet botnet. Emotet was leveraged by other criminal groups including Mallard Spider and Wizard Spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with Emotet campaigns that delivered IcedID Lite as a follow-on payload; Proofpoint notes limited visibility into follow-on payload attribution.
TA542 is responsible for distributing Emotet malware via large-scale email campaigns, often using hijacked email threads or invoice-themed lures. They have recently resumed activity after a hiatus, updating their tactics and leveraging additional malware loaders such as IcedID and Bumblebee.
Conducted high-volume email campaigns delivering Emotet and adapted delivery methods amid Microsoft's macro-blocking changes, using VBA/XL4 macro documents and later XLL files and zipped LNK attachments.
A criminal group associated here with phishing-delivered loader activity used to deploy Emotet, grow the Epoch5 botnet, and establish contact with C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.