Emotet operators resumed large-scale phishing activity by sending emails from compromised organizational mail servers and using spoofed display names, reply-style subject lines, and topical lures such as IRS tax notices. Multiple reports found the messages commonly carried password-protected ZIP archives containing malicious Excel files with legacy Excel 4.0/XLM macros. After a user enabled editing or macros, the spreadsheet downloaded an Emotet payload from compromised or attacker-controlled URLs and launched it with regsvr32.exe, restoring Emotet’s foothold after its earlier disruption.
Researchers observed that infected hosts then contacted multiple Emotet command-and-control servers and could be repurposed as spambots to send additional phishing emails with malicious spreadsheet attachments, extending the campaign. Analysis across the reports identified packed DLL or OCX payloads, Windows service persistence, and follow-on risk including delivery of tools such as Cobalt Strike or SystemBC. The references also published hunting and detection material, including Microsoft 365 Defender KQL queries, file hashes, domains, IP addresses, and JA3/JA3S TLS fingerprints, while noting that the campaigns continued to succeed partly because some environments still allowed Office macros despite Microsoft hardening changes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
From 18 URLs extracted from the malicious spreadsheets, Netskope found four still online and delivering Emotet at the time of analysis, and extracted three different 64-bit DLL payloads.
Netskope found 776 malicious Excel spreadsheets submitted to VirusTotal between June 9 and June 21 that abused Excel 4.0 macros to download and execute Emotet payloads.
Netskope said it had previously analyzed an April 2022 Emotet campaign that used LNK files instead of Microsoft Office documents.
As of March 23, NVISO said the Emotet malspam campaign that began on March 10 was still ongoing, though its frequency appeared to be decreasing.
NVISO observed a large Emotet malspam campaign beginning on March 10 that used compromised organizational mail servers, spoofed display names, and password-protected ZIP files containing macro-enabled Excel documents.
Fortinet reported that several transactions had been made to the Bitcoin wallet used in the Ukraine-themed donation scam since the campaign was discovered on March 7.
Palo Alto Unit 42 shared screenshots and indicators of compromise from an Emotet infection, which later supported additional traffic analysis.
The domain seca[.]cam, later used in a Ukraine-themed donation scam impersonating the United Nations, was registered.
Microsoft announced in January 2022 that Excel 4.0 macros were disabled by default starting in Excel build 16.0.14427.10000.
Emotet returned and resumed targeting organizations globally across multiple sectors following the 2021 disruption.
Europol and other law enforcement authorities disrupted Emotet, after which Emotet malicious spam and phishing activity dropped significantly for several months.
Fortinet noted that Microsoft moved to restrict VBA macros by default in Access, Excel, PowerPoint, Visio, and Word starting in April 2022.
FortiGuard Labs documented an IRS-impersonation phishing campaign delivering Emotet via a password-protected ZIP archive containing an Excel 4.0 macro-enabled file that downloaded malware from multiple remote locations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
netskope.com
Open sourcenetresec.com
Open sourceblog.nviso.eu
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.