Threat researchers reported that malware operators, including Emotet and QBot, have increasingly used binary padding to evade sandbox analysis and frustrate reverse engineering by inflating portable executable files with junk data while preserving functionality. The technique alters file hashes and can be applied through PE overlays, padded resource sections, gaps between sections, or oversized variables; low-entropy bytes such as repeated 00 values are especially effective because they compress well inside ZIP archives. Researchers also highlighted a compressed-padding variant known as PufferPhishing, which produces unusually large binaries that remain practical to deliver through phishing attachments.
Emotet campaigns illustrate how the tactic fits into broader phishing-driven intrusion chains. Recent outbreaks used malicious Office documents and Excel 4.0 macros to trick users into enabling content, then downloaded DLL payloads from hardcoded or macro-generated URLs and executed them with tools such as regsvr32.exe or rundll32.exe. In one documented case, an Emotet DLL grew from about 616 KB to 548.1 MB through 00-byte padding before being compressed for delivery, while post-infection activity included credential theft, spam distribution, reconnaissance, and process hollowing. Historical reporting also tied payload inflation to groups such as BRONZE BUTLER, showing that file-padding and oversized-payload evasion have been used across multiple malware operations for years.

Get the actors, campaigns, and ATT&CK mapping behind it.
12 events from the most recent confirmed update back to the earliest known activity.
In March 2023, Trend Micro documented Emotet using 00-byte padding in the PE overlay to inflate a DLL from 616 KB to 548.1 MB while still compressing efficiently for delivery. The report described this as an evasion method to exceed sandbox and scan-engine file-size limits.
From the end of February through the end of March 2022, Fortinet observed the campaign primarily reusing the 2021_NovW4 malicious Excel document type with different phishing templates. The report said this sample family accounted for more than half of malicious documents seen in the campaign.
Fortinet reported that the Emotet maldoc campaign surged again after January 12, 2022, with more frequent and consistent attacks. This marked an escalation following the initial late-2021 resurgence.
VMware observed a recent Emotet campaign that started on January 11 and peaked on January 12, 2022, affecting some VMware customers mostly in the EMEA region. The campaign used weaponized Excel 97-2003 documents with heavily obfuscated XL4 macros to download and run Emotet DLLs.
Fortinet reported that the first attack in its analyzed Emotet maldoc campaign appeared on November 16, 2021. The campaign spread through phishing emails carrying malicious Office documents and continued with changing sample types over subsequent weeks.
New Emotet activity was observed again on 2021-11-15, marking the botnet's return after the January 2021 takedown. The revived campaign used spoofed reply-chain phishing emails with Excel, Word, and password-protected ZIP attachments.
A recurring Emotet sample type tagged 2021_NovW4 first appeared in the fourth week of November 2021 and used Excel 4.0 macros to download and execute Emotet via regsvr32.exe. Multiple reports highlighted this as a notable shift from Emotet's historically VBA-heavy delivery methods.
Law enforcement and judicial authorities worldwide took down the Emotet botnet infrastructure in January 2021. Later reporting described subsequent Emotet activity as a return after this disruption.
Picus published technical analysis of a recent Emotet Epoch 2 Word document that used heavily obfuscated VBA macros, WMI, and a hidden PowerShell command to launch malware. The report documented delivery links, document hashes, and multiple defense-evasion techniques used in the sample.
Secureworks reported BRONZE BUTLER targeting Japanese businesses using a downloader that fetched a payload and appended the character '0' to inflate the file size to roughly 50 MB to 100 MB. This was cited as an early example of binary padding used for evasion.
Emotet was first identified in 2014 as a banking trojan focused on stealing sensitive information and financial credentials. It later evolved into a modular botnet used to deliver additional malware.
Intezer described a compressed binary-padding delivery technique it called 'PufferPhishing,' in which malware can be hundreds of megabytes on disk yet shrink by more than 90% inside ZIP archives. The article also highlighted recent phishing campaigns using this approach, including examples involving Emotet and QBot.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 103 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcetrendmicro.com
Open sourcefortinet.com
Open sourceblogs.vmware.com
Open sourceisc.sans.edu
Open sourcepicussecurity.com
Open sourceattack.mitre.org
Open sourcesecureworks.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.