The Emotet malware operation changed its infection tactics as Microsoft tightened default protections around Office macros, a long-used initial access method for malware delivered through phishing documents. Reporting indicates the group adapted its delivery chain to preserve access to victims despite the reduced effectiveness of malicious macro-enabled attachments.
The shift highlights how defensive changes by major software vendors can force established threat actors to retool rather than disappear. For defenders, the development underscores the need to monitor for alternative attachment and execution methods linked to Emotet campaigns, review email security controls, and harden endpoints against follow-on payload delivery after initial compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By January 2023, security reporting showed threat actors were increasingly using Microsoft OneNote attachments as a malware delivery method. This reflected a broader adaptation in initial access techniques following Microsoft's tightening of Office macro security.
On July 21, 2022, Microsoft announced that VBA macros would be blocked by default in Office documents downloaded from the internet, changing how users could enable macro content. The move significantly disrupted phishing campaigns that relied on malicious macro-enabled Office attachments.
A McAfee Labs report highlighted the rise of Windows LNK shortcut files as a malware delivery mechanism, reflecting attackers' shift away from traditional macro-enabled Office documents. This marked another tactical adaptation as defenders and platform vendors tightened macro-based infection paths.
By the time of ESET's June 16, 2022 report, Microsoft was tightening default Office macro security controls, and Emotet operators were adapting their delivery techniques in response. The report frames this policy shift and the malware group's resulting tactical changes as the key development.
Kroll observed that on April 22, 2022, Emotet operators changed the Epoch4 botnet subgroup’s loader delivery mechanism from malicious Office documents to password-protected ZIP archives containing malicious LNK shortcut files. The report says this was the first time Emotet had been seen using LNK files to package malicious PowerShell or VBScript in its infection chain.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcefourcore.io
Open sourcemcafee.com
Open sourcewelivesecurity.com
Open sourcekroll.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.