TA542, also known as Mummy Spider, MealyBug, and GoldCrestwood, is a Russian-speaking cybercriminal threat actor best known for developing, operating, and closely controlling the Emotet botnet and malware ecosystem. Emotet was first observed as a banking trojan in 2014 targeting banking customers in German-speaking Europe, then evolved into a modular trojan and later into a large-scale malware delivery platform and initial-access service used to distribute additional criminal payloads. TA542 has been associated with multiple Emotet botnet groupings, historically referred to as Epoch 1, Epoch 2, and Epoch 3, and later activity has also been linked to newer botnet epochs. TA542 primarily gains access through high-volume phishing and malspam campaigns, including malicious Office documents, password-protected archives, links to compromised websites, and later adaptations such as XLL files, zipped LNK delivery, and other techniques intended to bypass Microsoft macro hardening. The actor is particularly known for email thread hijacking, using stolen mailbox content and contact data from infected systems to craft convincing reply-chain phishing messages. Campaign themes have included invoices, delivery notices, job-related content, COVID-19 lures, government-related themes, and localized language content tailored to victim geography. Emotet under TA542 has supported credential theft, email and contact harvesting, password recovery from browsers and mail clients, and lateral movement inside victim networks through SMB exploitation and recovered credentials. The malware has also shown persistence, anti-analysis, and defense-evasion features, and later variants incorporated technical changes to loader behavior, communications, packing, and host-validation logic intended to hinder analysis and identify fake bots. TA542 has also been observed testing new delivery methods in lower-volume campaigns before returning to large-scale operations. A defining characteristic of TA542 is its role as a malware distributor for other criminal actors and payloads. Emotet has delivered QakBot, TrickBot, IcedID, Dridex, DoppelDridex, Gootkit, Nymaim, SilentNight, AZORult, MegaCortex, UmbreCrypt, and other malware families. Multiple reporting streams have linked Emotet-delivered access to downstream ransomware activity, including Ryuk, Conti, and ProLock, typically through second-stage malware chains rather than direct ransomware deployment by TA542 itself. TA542 has also been observed delivering an XMRig mining module during periods of reduced spam activity. Victimology is broad and generally opportunistic rather than sector-specific, with heavy impact documented in North America, Europe, and Japan. Government and public-sector entities, including French administrations and Lithuanian state institutions, have been targeted alongside private-sector organizations across many industries. TA542 is widely regarded as one of the most prolific financially motivated e-crime actors in the email threat landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
417 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with Emotet campaigns that delivered IcedID Lite as a follow-on payload; Proofpoint notes limited visibility into follow-on payload attribution.
TA542 is responsible for distributing Emotet malware via large-scale email campaigns, often using hijacked email threads or invoice-themed lures. They have recently resumed activity after a hiatus, updating their tactics and leveraging additional malware loaders such as IcedID and Bumblebee.
Operator cluster behind Emotet campaigns, using large-scale spam/phishing to deliver Emotet as a loader and initial access platform, including recent campaigns using thread hijacking, malicious Excel/XLM documents, social engineering to bypass Mark-of-the-Web/Protected View, regsvr32 execution, persistence via registry keys, and follow-on delivery of other malware.
Malspam operator distributing Emotet at high volume, using thread hijacking, localized lures, malicious Excel attachments with XL4 macros, and delivering follow-on payloads including IcedID; the report discusses its return, updated loader behavior, C2 changes, and regional targeting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.