Emotet is a long-running Windows malware family first identified in 2014 that began as a banking trojan and evolved into a modular loader and botnet used to deliver additional malware. It has been closely associated with large-scale criminal email operations, especially those attributed to TA542, also known as Mummy Spider. Emotet campaigns have historically relied on phishing and spearphishing lures themed as invoices, payments, shipping notices, or hijacked email threads, using malicious Office documents, macros, Excel 4.0 content, XLL add-ins, password-protected archives, and later container and shortcut-based delivery methods as operators adapted to Microsoft macro hardening. HTML smuggling has also been associated with later delivery tradecraft.
On execution, Emotet commonly uses staged infection chains involving native Windows utilities and scripting engines such as mshta, PowerShell, rundll32, regsvr32, and other living-off-the-land components to retrieve and launch follow-on payloads. It has been observed downloading DLL or executable payloads, unpacking or decrypting code in memory, and executing additional malware families including TrickBot. Technical analyses describe Emotet as polymorphic and heavily obfuscated, with runtime string and resource decryption, dynamic API resolution, control-flow obfuscation, and randomized network request elements intended to hinder analysis and signature-based detection.
Persistence mechanisms vary by privilege level and campaign. Reported methods include creation of Windows services when elevated, Run-key persistence in user context, and self-copying or renaming into system or user-accessible directories before relaunching a second-stage bot component. Emotet maintains command-and-control communications using encrypted protocols and can receive commands to download and execute binaries, launch payloads in other user sessions, or load plugin modules. Its modular architecture and botnet design have made it a flexible access platform for broader criminal operations.
Although widely remembered as a banking trojan because of its early focus on financial data theft, Emotet became more significant as an initial-access and malware-delivery platform used to establish footholds that enabled post-compromise activity, lateral movement by follow-on tooling, data theft, and eventual ransomware deployment in some intrusions. It has affected organizations across sectors globally and remains one of the most recognizable malware families in the email-borne threat ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Emotet has been known to move from machine to machine by leveraging a server message block (SMB) vulnerability exploit like ETERNALBLUE or by brute-forcing credentials for access to Windows Administrative Shares.
In late 2023, Microsoft and the U.S. National Institute of Standards and Technology (NIST) reported that attackers were using a Windows vulnerability to distribute malware, including Emotet... The technique involved phishing emails with malicious attachments that leveraged a Windows feature known as the App Installer... To reduce the risk of exploitation, Microsoft updated the software to disable the affected functionality by default.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An observed attack chain for this technique was provided by NETBYTESEC, detailing an infection flow with Emotet obtaining initial access through the execution of a malicious document...
According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.
SilentBuilder is a campaign that is being used to launch bankers such as Emotet to increase the Epoch5 botnet...
Emotet has relied upon users clicking on a malicious attachment delivered through spearphishing.
Le 11 mars 2022, le compte Twitter @Cryptolaemus1 a identifié la distribution d’un implant SystemBC par le botnet Epoch 5 lié au Malware-as-a-Service (MaaS) Emotet.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
According to SocRadar, the group exploits zero-day vulnerabilities to bypass security defenses and has deployed malware including GrandCrab and Emotet.
Emotet primarily spreads through phishing emails. These emails often appear legitimate, containing familiar branding and enticing subjects like invoices, payment details, or shipping notifications.
The suspicious email was received by our client. The malicious attachment seems to be an Emotet malware... Emotet is a Trojan that primarily spreads through malicious spam attachments... Spearphishing Attachment Upon opening the victim’s suspicious email attachment.
it contains interesting functions that will run automatically when opened
Investigating the Excel file... found that there is a malicious Excel 4.0 macro stored inside the Excel file.
The intrusion began when a user open a malicious document received through an email and enabled the content.
we found all the functions obfuscated and disordered. In one of the sheets, we find the most important function, which would deobfuscate most of the functionality
Netbytesec malware analyst noticed that the attackers used DNS name spoofing to impersonate their display name as a legitimate user.
305 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as malware deployed by the Unsafe ransomware group during intrusions.
Emotet1
Loader used to gain initial access before SystemBC deployment.
Referenced as malware that adopted HTML smuggling as an alternative delivery technique when macro-based delivery became less effective.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.