Researchers identified a politically aligned Emmenhtal campaign that used conference-themed lures to target organizations in the European energy sector. Around mid-October, attackers sent .lnk files, likely through spear phishing, themed around the 21st Gas Infrastructure Europe conference in Munich. The shortcut files launched PowerShell and mshta.exe, which retrieved an HTA payload hidden in the padding of a legitimate PE file hosted on attacker-controlled infrastructure. The infection chain then displayed a decoy PDF while deploying a malicious DLL known as Edam Dropper.
Edam Dropper established persistence through a Windows Run registry key and downloaded a final payload from a separate command-and-control server. The infrastructure supporting the operation was hosted on compromised WordPress sites in Ukraine and Poland and disguised as conference-related content. The activity stands out from Emmenhtal’s more common role in financially motivated malware delivery, including commodity infostealers, and researchers said the targeting and tradecraft may link the operation to Sandworm / APT44, which has a known interest in European energy networks.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers monitoring new Emmenhtal activity identified a politically aligned campaign that diverged from the loader's usual commodity-infostealer distribution. The chain delivered a malicious DLL dubbed Edam Dropper and the activity was assessed as possibly linked to Sandworm/APT44.
Orange Cyberdefense published research describing Emmenhtal as a little-known loader used to distribute commodity infostealers on a global scale. This established the loader's more typical financially motivated use prior to the later politically aligned activity.
Around mid-October, attackers used Emmenhtal in a campaign themed around the 21st Gas Infrastructure Europe conference in Munich, likely targeting organizations in the European energy sector. The infection chain used LNK lure files, likely delivered via spear phishing, and infrastructure disguised as conference-related content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.