Emotet is a modular Windows banking trojan and botnet malware family first observed in 2014. Initially focused on harvesting banking information, it evolved into a high-volume malware distribution platform and early-stage implant capable of downloading task-specific modules and delivering additional malware, including QakBot, TrickBot, and Ryuk. Emotet has been used to steal victims' email inbox contents, contact lists, and SMTP credentials, enabling email-thread hijacking and forged malicious messages that improve phishing effectiveness. Infected hosts may also be used as spam bots. Emotet communications use encrypted command-and-control channels and may exhibit low-frequency beaconing with significant jitter. Later 64-bit variants dynamically calculate configuration data, cryptographic key material, command-and-control data, and strings at runtime, using mixed Boolean-arithmetic and control-flow-flattening obfuscation to impede static analysis and signature creation. International law-enforcement action disrupted Emotet infrastructure in January 2021, but the family subsequently re-emerged in cybercrime activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In Microsoft’s December 14, 2021, Patch Tuesday vulnerability release, security patches were released for a high severity zero-day vulnerability impacting the Windows AppX installer. The vulnerability is tracked as CVE-2021-43890 (CVSS: 7.1). Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application. Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader. | Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader.
Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. | Emotet has used HTTP for command and control... Emotet has been delivered by phishing emails containing attachments... Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.
As soon as the proof-of-concept (PoC) for CVE-2020-9054 was made publicly available last month, this vulnerability was promptly abused to infect vulnerable versions of Zyxel network-attached storage (NAS) devices with a new Mirai variant - Mukashi.
Emotet has previously exploited CVE-2017-11882, a remote code execution flaw in the Microsoft Equation Editor. Detection network connections from eqnedt32.exe can be an indicator of exploit. | Kroll has been tracking Emotet since it was first identified in 2014, especially during its transition from a banking Trojan designed to primarily steal credentials and sensitive information to a multi-threat polymorphic downloader for more destructive malware.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
Emotet has been delivered by phishing emails containing attachments.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“It turned infected systems into spam bots... The malware would exfiltrate each victim’s email inbox, contact list, and SMTP credentials. That data was then used to forge malicious emails originating from the victim’s email address.”
When the macro is executed a PowerShell command is used to retrieve an Emotet payload from another compromised domain.
When the macro is executed a PowerShell command is used to retrieve an Emotet payload from another compromised domain.
In the newer versions the configuration is calculated at runtime... hidden within the actual code. The malware uses Mixed Boolean-Arithmetic (MBA) as one of its obfuscation techniques.
The configuration was stored in an encrypted form in the .data section of the binary. In the newer versions the configuration is calculated at runtime.
The chosen malware sample belongs to the emotet family and has been already described in a previous blog post, in which we analyzed its control-flow flattening implementation.
eSentire observed interactive operators arrive on the compromised asset within one hour of initial infection.
Some of the common protocols used for C2 are HTTP/S, DNS, SSH, and SMTP, as well as common cloud services like Google, Twitter, Dropbox, etc. Using common protocols and services for C2 allows adversaries to masquerade as normal network traffic and hence evade firewalls.
The ECDSA key (ECC1) is used for verifying the C2 server's responses... identifying and discovering which C2 servers they use to operate their network.
3,145 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware that propagated through forged and malicious email campaigns. It stole email inboxes, contact lists, and SMTP credentials from victims, abused trusted relationships, and later replied to existing email threads to distribute malware-laden messages.
Emotet is described as a downloader used to deliver TrickBot in multi-stage intrusion chains that later led to ransomware deployment.
Modular malware first observed in 2014 that started as a banking trojan and later evolved into a loader used to deliver additional payloads.
Mentioned only as a comparison point after its takedown in early 2021; no campaign-specific behavior is analyzed here.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.