TA542, also known as Mealybug and MUMMY SPIDER, is a long-running financially motivated cybercrime threat actor best known for operating Emotet. Active since at least 2014, the group initially used Emotet as a banking trojan targeting banking customers in Europe, particularly Germany and later Switzerland, before evolving it into a modular malware platform and large-scale malware delivery service for other criminal actors. TA542’s operations center on malicious email campaigns for initial access, including weaponized Office documents, links to downloader content, password-protected archives, thread-hijacking and reply-chain lures, and later alternative attachment formats such as LNK, XLL, OneNote, and App Installer-based delivery chains. Emotet has been used to establish persistence, collect host information, steal credentials and other sensitive data, exfiltrate victim information, send spam from compromised systems, and propagate laterally inside networks through brute-force activity and worm-like spread. The malware has also incorporated anti-analysis and defense-evasion features, including obfuscation, environment checks, control-flow flattening, randomization, and encrypted command-and-control communications. The group has repeatedly used Emotet to deliver additional malware for downstream monetization, including IcedID, TrickBot, Qakbot, Gootkit, and ransomware such as UmbreCrypt. Reporting has characterized TA542 as an end-to-end malware delivery service that likely profits by enabling follow-on intrusions by other threat actors rather than exclusively operating all secondary payloads itself. Post-compromise activity associated with Emotet infections has included credential theft, email account theft, browser data theft, theft of stored payment card data, spambot operations, and deployment of post-exploitation tooling such as Cobalt Strike. TA542 resumed operations in late 2021 after an international law-enforcement disruption earlier that year and subsequently updated Emotet with 64-bit modules, elliptic-curve cryptography, enhanced obfuscation, and expanded information-stealing modules. The actor has targeted both individuals and organizations globally, with observed activity affecting North America, Europe, Asia, and Africa. Its campaigns have had significant operational impact on victims because of rapid internal spread, account lockouts, follow-on malware delivery, and broad disruption to enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
225 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to Emotet activity; associated with operations involving the Emotet malware, which evolved from banking credential theft into a broader threat-delivery service.
Operator of the Emotet botnet, conducting large-scale spam and malspam campaigns, using email thread hijacking, malicious attachments, credential theft, information stealing modules, and botnet evasion/anti-analysis improvements.
Operator behind Emotet, conducting large-scale email-distributed malware campaigns using malicious attachments, links, macros, thread hijacking, spambot activity, and delivery of additional payloads after infection.
Initially targeted banking customers in Europe using Emotet to deliver banking trojans, then evolved into a global malware delivery service for other threat actors, using spam, malicious documents/links, brute-force network propagation, and modular payload delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.