Emotet is a long-running cybercriminal malware operation and botnet that emerged in 2014 as a banking trojan and later evolved into one of the most prominent malware loaders and initial access broker ecosystems. It is widely tracked as both a malware family and the criminal operation behind it. The operation has historically organized infected systems into separate botnets known as Epochs, including Epoch 1 through 5, with later activity centered on Epoch 4 and Epoch 5. Emotet initially focused on theft of banking credentials and financial information, then shifted toward large-scale spam-driven compromise and malware delivery. Its operators have repeatedly used malicious email campaigns, including hijacked reply-chain threads, spoofed business communications, password-protected archives, macro-enabled Office documents, Excel 4.0 macros, and later LNK-based delivery chains. Recent campaigns have used PowerShell, regsvr32, and modular DLL loaders, including 64-bit loaders, to establish infection. Once executed, Emotet commonly decrypts and reflectively loads an internal payload in memory, uses API hashing and encrypted strings for obfuscation, dynamically resolves Windows APIs, and communicates with command-and-control infrastructure over encrypted HTTP. It supports persistence through user-run keys or services and includes modules for credential theft from browsers and email clients, spam propagation, proxying, and SMB-based lateral movement. Emotet has also demonstrated defense-evasion techniques such as heavy obfuscation, benign-code insertion, anti-emulation logic, dynamic API resolution, and in-memory loading designed to hinder static and forensic analysis. The operation is notable for turning compromised hosts into a malware-as-a-service platform. Emotet infections have been used to deliver additional payloads including QakBot, TrickBot, Gootkit, Cobalt Strike, SystemBC, ransomware, information stealers, crypto-miners, and banking trojans. Security reporting has repeatedly characterized Emotet operators as prominent initial access brokers that monetize footholds by selling or leasing access to other criminal actors. Infections are frequently treated as precursors to broader enterprise compromise, data theft, and ransomware deployment. Emotet was disrupted by a major international law-enforcement action in early 2021 but resurfaced later that year and resumed global spam operations with updated delivery and evasion techniques. Post-resurrection activity has been linked in reporting to closer operational overlap with TrickBot and the Conti ecosystem, including repeated deployment of Cobalt Strike after infection. The dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adopted HTML smuggling as an alternative delivery method when macro-based delivery became less effective.
Mentioned only as the name of an associated analytic story in Splunk content metadata.
Mentioned only as part of an associated analytic story list for a removed Splunk detection.
A botnet operation disrupted by law enforcement; used a modular loader to steal credentials and bank details and distribute other malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.