Emmenhtal is a Windows-focused, multi-stage malware loader first observed in 2024 and used predominantly in financially motivated malware-delivery operations. It employs heavily obfuscated JavaScript, HTA, PowerShell, and occasionally polyglot-file stages to retrieve, decrypt, and execute subsequent payloads. Its execution chains commonly use legitimate Windows scripting utilities, encoded commands, in-memory .NET loading, and AMSI-evasion attempts to reduce visibility and evade endpoint defenses.
Emmenhtal has delivered commodity malware including Amadey, SmokeLoader, Lumma Stealer, Danabot, and other information stealers or remote-access tools. It has been distributed through ClickFix/FakeCaptcha social engineering, in which victims are induced to paste attacker-provided commands into the Windows Run dialog; campaigns have also used phishing and spearphishing attachments, malicious shortcuts, archive files, compromised websites, malvertising, and public code repositories. Some variants use audio or other benign-looking files carrying embedded script content, as well as legitimate executable padding to conceal HTA content.
Observed activity includes financially motivated campaigns targeting Ukrainian organizations and a campaign using energy-sector conference lures against organizations in Europe. Emmenhtal has appeared in malware-as-a-service and traffic-distribution ecosystems that provide payload delivery for multiple downstream operators. The name Peaklight has also been used by some vendors for a related final-stage PowerShell downloader component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Around mid-October, an infection chain leveraged lure documents related to the 21st Gas Infrastructure Europe (GIE) conference in Munich, possibly targeting organizations in the European energy sector. Threat actors distributed LNK files ... in order to deploy the Emmenhtal loader.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Users encounter a CAPTCHA page that mimics a legitimate human verification prompt, often while browsing seemingly harmless content websites.
These fake CAPTCHAs arrive via phishing emails, URL redirection or malvertisement, or SEO poisoning.
In some cases, the phishing emails attach a PDF instead of including a direct link. Once opened, the PDF redirects the user to a fake CAPTCHA landing page.
The embedded URLs in each phishing email exploit the credibility of legitimate domains such as https://xxx[.]51.ca and hxxps://www[.]xxxnet.dk, to appear trustworthy to unsuspecting users. Once clicked, however, these URLs redirect users to the landing pages of the fake CAPTCHA domains.
The command uses ROT cipher or XOR obfuscation... powershell.exe -ep bypass -c iex ...
The scheduled task launches PowerShell through a wildcard path with -EncodedCommand; the next stage runs entirely in memory.
Talos discovered another unique file on the “Milidmdds” GitHub account during this research — a malicious Python script named “checkbalance.py”.
These sites are now hosting specially crafted .mp3 files containing injected and highly obfuscated JavaScript.
A compromised site has an injected snippet which delivers a fake captcha prompt... instructs the end user to press Windows Key + R... [then] Control + V and enter... detonates the command.
When lyricalsync.mp3 is executed via mshta, it initiates a multistage deobfuscation process designed to evade detection mechanisms.
The malicious HTA data located in the padding of this PE file corresponds to Emmenhtal‘s first stage
Emmenhtal recovers its payload from a steganographic JPEG hosted on a legitimate image CDN; pixel-block averages encode the encrypted payload.
The JavaScript is decrypted using a key... to get a PowerShell script (PS_A)... which uses AES decryption with a hardcoded key, to get another PowerShell script (PS_B).
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage PowerShell loader delivered during the fileless stage. It retrieves an encrypted payload concealed in a steganographic JPEG from a legitimate image CDN, then reflectively loads the resulting PE in memory without writing the final payload to disk.
A loader used in the fake CAPTCHA campaign. It is embedded as obfuscated JavaScript inside crafted MP3 files and executed through mshta, then deobfuscates in multiple stages and retrieves additional payloads such as stealers and RATs.
Emmenhtal is referenced as a malware loader used to propagate Amadey.
A heavily obfuscated PowerShell loader/downloader that uses large amounts of junk math operations, embedded base64 byte arrays, XOR decoding, and .NET reflection-based execution to load and run a payload while evading static analysis and sandboxing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.