Researchers and government analysts documented how Emotet hides its functionality through API hashing, dynamic API resolution, string encryption, junk code, stack tricks, and control-flow flattening, complicating reverse engineering of unpacked samples with empty import tables. Sophos reported that, across 254 examined functions, 68 used flattened control flow; researchers fully unflattened 38, partially restored 19, and failed on 11 while adapting IDA-based tooling to handle multiple dispatchers and other edge cases.
Technical work from JPCERT/CC and open-source tooling showed that analysts can automate large parts of Emotet analysis with Ghidra and Binary Ninja plugins, including annotating hashed APIs, decrypting strings, and extracting hardcoded command-and-control endpoints from internal configuration data. ANSSI described Emotet as a malware-as-a-service platform operated by TA542, spread largely through phishing, malicious Office attachments, thread hijacking, compromised WordPress sites, and direct IP-based C2, and linked it to downstream payloads including TrickBot, QakBot, Dridex, Conti, and Ryuk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
24 events from the most recent confirmed update back to the earliest known activity.
During the week of May 9, 2022, an updated Emotet x64 variant changed its configuration storage by generating strings, cryptographic material, and C2 data via obfuscated stack-string routines instead of keeping encrypted values statically in the binary. OALABS showed these artifacts, including key blobs and numerous C2 endpoints, could be recovered by identifying and emulating the relevant functions with Dumpulator.
Sophos observed Emotet payloads repeatedly in its sandbox systems during the first quarter of 2022 and assessed detection spikes as likely tied to large-scale distribution campaigns.
Sophos reports that Emotet re-emerged in November 2021 after nearly a year of reduced activity following the January 2021 disruption.
Sophos states that a multinational law enforcement operation disrupted the Emotet botnet in January 2021.
Analysis of an Emotet sample from a campaign observed around December 2020 reconstructed its infection chain from zipped-document phishing to PowerShell downloader and second-stage DLL execution. The research detailed state-machine obfuscation, Windows service persistence in this variant, encrypted string and C2 storage, and RSA/AES-protected command-and-control communications, and published hashes and extracted C2 infrastructure.
The repository history shows a commit labeled "Remove useless function" for the Emotet API and string deobfuscator plugin on September 21, 2020.
The GitHub repository history shows the initial commit for Francesco Muroni's Emotet API and string deobfuscator plugin on August 5, 2020.
ANSSI notes that from August 2020, Emotet thread-hijacking phishing campaigns targeted both private and public sectors in France.
ANSSI states that a July 2020 campaign delivered an infection chain involving Emotet, TrickBot, and Ryuk or Conti.
ANSSI reports that in July 2020, TA542 used a GitHub-available webshell with a shared password on compromised WordPress sites, and a white-hat actor replaced some Emotet payloads with harmless GIFs.
ANSSI reports that in March 2020, a coronavirus-themed Emotet campaign in Japan delivered TrickBot as a second-stage payload.
ANSSI describes a February 2020 SMS phishing campaign in which messages spoofing banks warned of account closure and redirected victims to fake banking pages that distributed Emotet.
ANSSI says that since 2019, Emotet phishing emails have more commonly carried malicious Word, PDF, or ZIP attachments, though URL-based lures continued.
ANSSI reports that in 2018, about 66% of Emotet phishing emails impersonated real entities such as DHL, PayPal, or UPS.
ANSSI states that in 2018, about 98% of Emotet campaign emails contained a URL leading to a malicious Office document download.
ANSSI reports that since 2018, TA542 has used thread hijacking by stealing email content from compromised mailboxes and replying within legitimate conversation chains.
ANSSI states that Emotet appeared in March 2017 and broadly uses the name for Geodo versions spanning 2014 to 2020.
Since 2017, ANSSI says Emotet has primarily served as a loader for malware operated by TA542 clients rather than as a banking trojan.
From 2015 onward, ANSSI says Emotet evolved from a banking trojan into a modular malware platform capable of stealing passwords, browser credentials, email data, and contact lists.
ANSSI reports that TA542 advertised Emotet on underground forums until 2015, after which the service became private.
The ANSSI report states that after the FBI dismantled GameOverZeuS infrastructure in May 2014, Dridex and Geodo emerged from remnants of the Business Club.
Sophos describes Emotet as a long-running cybercrime malware service and botnet that has been active since 2014.
ANSSI links the origin of the Geodo malware lineage to the Business Club cybercriminal group, whose activity began around 2008.
Sophos analyzed unpacked Emotet samples, identified 68 flattened functions out of 254 analyzed, and released an IDAPython-based tool on the SophosLabs GitHub repository to deobfuscate portions of the malware's control flow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourceresearch.openanalysis.net
Open sourcegithub.com
Open sourcegithub.com
Open sourcejsac.jpcert.or.jp
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.