Emotet resumed large-scale operations after a months-long lull and launched widespread phishing campaigns against enterprises, governments, and international organizations, using invoice lures, malicious Office documents, links to compromised WordPress sites, and increasingly convincing reply-chain emails built from stolen mailbox content. Cisco Talos said sinkholed SMTP domains exposed hundreds of thousands of malicious emails per month and infections across more than 200 countries, while ANSSI warned that French companies and public administrations were being actively targeted and that the malware was again being distributed through the TA542 botnet infrastructure across multiple epochs.
The renewed activity restored Emotet’s role as a high-volume initial-access platform that frequently delivered TrickBot, Qbot, and other payloads that enabled credential theft, lateral movement, and eventual ransomware deployment including Ryuk and Conti. Reported incidents included phishing aimed at 600 United Nations addresses, infections at Lithuania’s National Center for Public Health and municipalities through password-protected archives sent in hijacked email threads, and a municipal case in Germany where an Emotet-linked intrusion escalated into widespread encryption and a full IT rebuild, reinforcing guidance to isolate infected hosts, investigate for broader compromise, and favor reinstallation over antivirus-only cleanup.

Get the infrastructure and lures behind it.
20 events from the most recent confirmed update back to the earliest known activity.
A new Emotet phishing campaign used stolen reply-chain emails linking to fake Google Drive pages, where a 'Preview PDF' button launched an ms-appinstaller URL to install a malicious package posing as Adobe PDF software. The package was hosted on Microsoft Azure and used Windows App Installer to execute Emotet and establish persistence on victims' systems.
On 2021-11-14, researchers observed bots in several Trickbot botnets downloading a DLL that sandbox and manual analysis identified with high confidence as a reincarnation of Emotet. The sample showed behavior and obfuscation resembling historical Emotet activity while also using changes such as different encryption and HTTPS with a self-signed certificate.
In January 2021, an international law enforcement operation coordinated by Europol and Eurojust took control of Emotet's botnet infrastructure and redirected infected machines to infrastructure under authorities' control. The action involved multiple countries and included arrests in Ukraine.
The Lithuania-focused report states that the Emotet botnet resumed activity on December 21, 2020, after a break of about a month and a half.
Lithuania's National Center for Public Health and several municipalities were infected during a large Emotet campaign targeting Lithuanian state institutions. The phishing emails used reply-chain lures and password-protected archives to evade some anti-malware detection.
Lithuania's National Cyber Security Center detected a previous large Emotet campaign in October 2020 and afterward advised state institutions and companies to enable and properly configure SPF email authentication.
In September 2020, ANSSI warned that French companies and public administrations were being targeted by Emotet phishing campaigns and highlighted the risk of follow-on malware and ransomware deployment.
Several references report that Emotet resurfaced in mid-July 2020 after more than five months of inactivity, restarting large spam campaigns with malicious documents.
BleepingComputer reported that after returning in July 2020, Emotet again began installing TrickBot on infected Windows machines, reviving a common infection chain associated with later ransomware risk.
Cisco Talos reported that starting in February 2020, Emotet took an extended break from spamming that lasted several months.
On 2020-01-22, CISA said it was aware of a recent increase in targeted Emotet malware attacks. The agency warned that Emotet could spread via malicious attachments and laterally inside networks, and issued mitigation guidance including attachment blocking, segmentation, patching, and DMARC.
Cisco Talos obtained ownership of several abandoned domains previously used by Emotet for SMTP communications and sinkholed them, gaining visibility into hundreds of thousands of Emotet emails per month and infected systems worldwide.
Cofense observed a targeted Emotet phishing campaign sent to 600 unique email addresses associated with United Nations users, impersonating the Permanent Mission of Norway and using a malicious Word attachment. No confirmed victims were known at the time of reporting.
On the morning of 6 September 2019, Neustadt am Rübenberge detected unusually high server utilization and found widespread encryption, including a workstation showing a Ryuk ransom note. The city ordered employees to shut down systems, warned partners, notified police and the data protection authority, and received investigators the same morning.
Unknown attackers began encrypting the city administration of Neustadt am Rübenberge's servers on the evening before or during the night before 6 September 2019, affecting municipal data and accounting records.
The Heise article says Germany's BSI reported that within a few days in September, Emotet compromised several thousand email accounts belonging to companies and private citizens in Germany and abused them for spam distribution.
The Heise article says the publisher itself suffered an Emotet infection in May 2019, though it did not lead to a full shutdown or data encryption.
ANSSI said that since 2017 Emotet has mainly been used as a loader for third-party malware rather than as a banking trojan, delivering payloads such as Qbot, TrickBot, IcedID, GootKit, BokBot, Dridex, and DoppelDridex.
Multiple references state that Emotet was first identified or observed in 2014 as a banking trojan before later evolving into a modular loader and botnet-delivered malware platform.
NVSC temporarily shut down its email systems on a Tuesday to prevent further spread, while its IT staff worked with the Central State Telecommunications Center and the National Cyber Security Center to clean systems and restore email access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
11 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourceinfosecurity-magazine.com
Open sourcebleepingcomputer.com
Open sourcecyber.wtf
Open sourcebleepingcomputer.com
Open sourceheise.de
Open sourceus-cert.gov
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.