Emotet, also known as Geodo or Heodo, is a modular Windows malware family first identified in 2014 that evolved from a banking trojan into one of the most prominent malware delivery platforms and botnets in cybercrime. It has been associated with the threat actor commonly tracked as Mealybug and has been widely used to steal banking credentials, harvest email and contact data, retrieve additional payloads, and enable follow-on intrusions that culminate in ransomware deployment. Emotet has historically served as an initial-access and malware distribution layer for other criminal operations, including delivery chains involving TrickBot, Qakbot, Dridex, IcedID, Ryuk, Conti, DoppelPaymer, and other payloads.
Emotet is primarily distributed through malicious email campaigns, including phishing and malspam using weaponized Microsoft Office documents or links to downloader documents. Social engineering commonly pressures recipients to enable macros, after which script interpreters are used to fetch and execute the payload. Once installed, Emotet relocates itself, establishes persistence, profiles the infected host, and communicates with command-and-control infrastructure using encrypted data. Observed host profiling includes system identifiers and running process information, and the malware has demonstrated anti-analysis logic in which server-side responses vary depending on the perceived analysis value of the victim environment. Later variants also used stronger obfuscation, including stack strings and protected configuration material.
The malware is highly modular. Documented capabilities include credential theft, especially banking and stored password theft; harvesting Outlook data and email addresses through MAPI; downloading and executing additional malware; and fileless loading of modules in memory. Emotet has also been observed abusing legitimate tools and process hollowing to steal credentials, including browser and mail passwords. Its email-harvesting functionality has supported further spam propagation and account abuse.
Emotet also exhibits worm-like behavior inside victim networks. Reported propagation methods include brute forcing user credentials and writing to shared drives, as well as use of a spreader module to move laterally across accessible systems. These behaviors have caused rapid internal spread and operational disruption in enterprise environments.
Operationally, Emotet became one of the largest botnets in the world before an international law-enforcement disruption in 2021, then resurfaced later that year. Its role as a large-scale loader made it strategically important in the cybercrime ecosystem because it supplied high-volume access to downstream malware and ransomware operators. Security professionals most commonly regard Emotet as a modular trojan and malware loader with strong credential-theft, propagation, and payload-delivery functions targeting Windows environments across multiple sectors worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. | Emotet has used HTTP for command and control... Emotet has been delivered by phishing emails containing attachments... Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.
As soon as the proof-of-concept (PoC) for CVE-2020-9054 was made publicly available last month, this vulnerability was promptly abused to infect vulnerable versions of Zyxel network-attached storage (NAS) devices with a new Mirai variant - Mukashi.
Emotet has previously exploited CVE-2017-11882, a remote code execution flaw in the Microsoft Equation Editor. Detection network connections from eqnedt32.exe can be an indicator of exploit. | Kroll has been tracking Emotet since it was first identified in 2014, especially during its transition from a banking Trojan designed to primarily steal credentials and sensitive information to a multi-threat polymorphic downloader for more destructive malware.
In late 2023, Microsoft and the U.S. National Institute of Standards and Technology (NIST) reported that attackers were using a Windows vulnerability to distribute malware, including Emotet... The technique involved phishing emails with malicious attachments that leveraged a Windows feature known as the App Installer... To reduce the risk of exploitation, Microsoft updated the software to disable the affected functionality by default.
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
Emotet has been delivered by phishing emails containing attachments.
Mealybug is identified by its use of its custom malware, Trojan.Emotet. Once on a computer, Emotet downloads and executes a spreader module that contains a password list that it uses to attempt to brute force access to other machines on the same network.
The Emotet malware is now distributed through malicious Windows App Installer packages that pretend to be Adobe PDF software.
First detected in 2014, Emotet is a modular, polymorphic trojan that is capable of evading signature-based detection and spreading throughout a victim network to compromise additional systems. Emotet often serves as a first–or second–stage malware that can drop and download further payloads...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
To this end, it steals the emails of its victims and replies to the victim’s previous conversations. This is known as email conversation thread hijacking. | While our mail filters are still detecting sporadic emails containing malicious Emotet documents... We expect that these last drips of Emotet malspam dripping out of the dying Emotet botnet to dry out over the next days and weeks.
EMOTET本体には、複数のC&Cサーバの接続先情報が暗号化された状態でハードコードされており、それらのC&Cサーバへ順に接続を開始します。
APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. APT29 also used PowerShell to create new tasks on remote machines, identify configuration settings, evade defenses, exfiltrate data, and to execute other commands. | AppleSeed has the ability to execute its payload via PowerShell... APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts and performs PowerShell commands... Start-Process / Invoke-Command / System.Management.Automation
In the end, the Macro executes the "tjspowj.vbs" file with “wscript.exe.” | The malicious Macro has a function called “Workbook_Open()” that is executed automatically in the background when the Excel file opens.
It then calls another function to write script data to a VBS file and save it in the "C:\ProgramData\" folder. Next, it uses "Wscript.exe" to execute the VBS file. | Script code in the HTA file extracts JavaScript code to download the Emotet malware.
The encrypted .zip file contained a malicious Microsoft Word document (maldoc) used to download and install the Emotet loader. | Upon opening Emotet maldocs, victims are greeted with fake Microsoft 365 prompt that states “THIS DOCUMENT IS PROTECTED,” and instructs victims on how to enable macros.
Figure 7 shows Wireshark recording the SMB spreader traffic, which represent the creation and the execution of a remote service... | ...the core Emotet DLL, as well as any other component executed by the core module, is running in a service hosted by regsvr32.exe under the SYSTEM account...
The code is obfuscated using Control Flow Flattening, which works as follows: A number is assigned to each basic block... The ordinary control flow is replaced with a switch statement over the block number variable, wrapped inside of a loop. | The names of the API functions are stored in the code after they were hashed. Their address is located in run-time instead of using the Import Address Table. The strings are encrypted inside the file. The code is obfuscated using Control Flow Flattening.
Cookieとして送られていた暗号化された文字列の中には、感染環境の以下のデータが含まれていることがわかりました。... 起動している全てのプロセスのリスト
Cookieとして送られていた暗号化された文字列の中には、感染環境の以下のデータが含まれていることがわかりました。 コンピュータ名 環境識別子 起動している全てのプロセスのリスト
The network traffic originating from the sample closely resembles what has been observed previously... the URL contains a random resource path and the bot transfers the request payload in a cookie. | Additionally, the sample now uses HTTPS with a self-signed server certificate to secure the network traffic.
3,137 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Emotet is described as a downloader used to deliver TrickBot in multi-stage intrusion chains that later led to ransomware deployment.
Modular malware first observed in 2014 that started as a banking trojan and later evolved into a loader used to deliver additional payloads.
Mentioned only as a comparison point after its takedown in early 2021; no campaign-specific behavior is analyzed here.
A botnet delivered in this campaign through malicious OneNote files that execute obfuscated VBScript to download a DLL, decrypt shellcode and a PE payload, reconstruct imports in memory, and execute the final Emotet payload while evading analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.