Threat researchers reported that Emotet, IcedID, and QBot were used as initial access malware to quickly deliver Cobalt Strike on compromised Windows systems, sharply reducing the time defenders had to respond before hands-on-keyboard activity began. In observed intrusions, reconnaissance started within 6 to 8 minutes of infection, while Cobalt Strike was deployed in as little as under an hour to roughly two hours later. The activity was commonly initiated through targeted phishing emails carrying malicious Office documents and macros, with follow-on use of PowerShell, scheduled tasks, Run keys, or services to establish persistence and pull additional payloads.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
On 2022-07-07, SANS ISC documented an Emotet malspam infection in a lab Windows host where a macro-enabled Excel attachment downloaded Emotet DLLs and led to delivery of a Cobalt Strike payload. The report published hashes, file paths, download URLs, and network indicators for both Emotet command-and-control traffic and the follow-on Cobalt Strike activity.
Cisco reported that Emotet showed increased activity from 2022 onward after its November 2021 re-emergence.
In December 2021, Emotet changed its infection chain to directly install Cobalt Strike beacons instead of first deploying TrickBot or Qbot/QakBot, according to BleepingComputer citing Cofense and other researchers.
Cisco said Emotet re-emerged in November 2021 following its January 2021 disruption.
Cisco reported that a combined law enforcement effort involving Interpol and Eurojust disrupted Emotet in January 2021.
Cybereason observed a broader mid-2021 "stolen images evidence" phishing campaign in which emails impersonated copyright complaints and led victims to download JavaScript that fetched IcedID.
Cisco observed an increase in IcedID banking trojan infections in late February and throughout March 2018, many delivered through spear-phishing Word documents that led to Ursnif/Dreambot and then IcedID.
Cisco said security researchers first reported IcedID in November 2017 and that, at the time of discovery, Emotet was distributing it.
Cisco stated that Emotet was first observed in 2014 as a banking trojan and modular malware family.
Cofense reported a limited number of Emotet infections that installed Cobalt Strike, attempted to contact lartmana[.]com, and then removed the executable shortly afterward.
Cybereason analyzed an intrusion attributed in part to Conti affiliates in which a targeted phishing email delivered IcedID, followed by reconnaissance, attempted privilege escalation, code injection, and Cobalt Strike deployment within roughly two hours.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 81 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open sourceisc.sans.edu
Open sourceblogs.cisco.com
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.