Emotet, also known as Geodo and Heodo, is a modular Windows malware loader and botnet that first appeared as a banking trojan in 2014. It evolved into a criminal malware-delivery service that provided other operators with access to compromised systems. Emotet distributes secondary payloads, notably TrickBot, and has enabled attack chains leading to Ryuk, Conti, and DoppelPaymer ransomware. Its role is primarily establishing compromise and delivering additional malware rather than performing ransomware encryption itself.
Emotet spreads through phishing and spam emails containing malicious attachments or download links. Campaigns have used hijacked email conversations, fraudulent public-health warnings, malicious Windows shortcuts, and password-protected archives that obstruct automated inspection. Its capabilities include deploying credential-harvesting modules such as Mimikatz, guessing account passwords using hard-coded lists, propagating laterally through Windows networks, and injecting code into legitimate processes. These behaviors support credential theft, further compromise, and concealed execution. Wizard Spider has used spearphishing attachments to deliver Emotet in ransomware-related operations.
Emotet's infrastructure has included several hundred servers and layered proxies across multiple botnets, with more than one million compromised hosts. An international law-enforcement operation disrupted it in January 2021, but it returned later that year and subsequently operated intermittently.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The flaw is designated as CVE-2020-9054. Holden said the exploit is now being used by a group seeking to fold it into Emotet, while Zyxel has released patches for some affected products.
InvisiMole can spread within a network via EternalBlue (CVE-2017-0144). Emotet, Lucifer, NotPetya, PoshC2, TrickBot, Tonto Team, and Wizard Spider are also explicitly linked to EternalBlue; Threat Group-3390 exploited MS17-010. | Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.
In Microsoft’s December 14, 2021, Patch Tuesday vulnerability release, security patches were released for a high severity zero-day vulnerability impacting the Windows AppX installer. The vulnerability is tracked as CVE-2021-43890 (CVSS: 7.1). Exploitation allows a threat actor to create a malicious file that appears to be a legitimate application. Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader. | Exploitation in the wild has been observed in the delivery of multiple malware types including: Emotet, Trickbot, and BazarLoader.
Emotet has previously exploited CVE-2017-11882, a remote code execution flaw in the Microsoft Equation Editor. Detection network connections from eqnedt32.exe can be an indicator of exploit. | Kroll has been tracking Emotet since it was first identified in 2014, especially during its transition from a banking Trojan designed to primarily steal credentials and sensitive information to a multi-threat polymorphic downloader for more destructive malware.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Emotet has been delivered by phishing emails containing attachments.
In 2019, a relationship between Emotet, TrickBot, and Ryuk ransomware was discovered, where the Ryuk ransomware operators were granted access to an organization through a TrickBot infection.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
In Dec 2019, the company’s researchers captured multiple conversations in hackers’ communities discussing the launch of EMOTET campaigns.
The Emotet botnet is back by popular demand, resurrected by its former operator, who was convinced by members of the Conti ransomware gang.
48 distinct techniques documented for this family, organized by ATT&CK tactic.
3,147 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spreads through phishing and installs secondary payloads, including QakBot and TrickBot, enabling subsequent ransomware attacks. The article describes repeated disruption, rebuilding, and intermittent activity after its January 2021 takedown.
Concealed its controllers behind multiple proxy tiers spanning compromised web servers and home computers. An international operation seized its infrastructure in January 2021, but it returned later that year.
Botnet malware that propagated through forged and malicious email campaigns. It stole email inboxes, contact lists, and SMTP credentials from victims, abused trusted relationships, and later replied to existing email threads to distribute malware-laden messages.
Emotet is described as a downloader used to deliver TrickBot in multi-stage intrusion chains that later led to ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.