Emotet re-emerged after the 2021 law-enforcement disruption and rebuilt its botnet through large-scale phishing and thread-hijacking campaigns that delivered malicious Office files, password-protected ZIPs, LNK files, and later OneNote lures. Across these waves, victims were tricked into enabling macros or opening shortcut-based droppers that launched obfuscated PowerShell, mshta.exe, JavaScript, or Excel 4.0/XLM macros to fetch Emotet DLLs from rotating lists of compromised websites, often executing them through regsvr32.exe or rundll32.exe. Researchers reported campaigns targeting millions of email addresses, with notable concentration in Japan and Italy, and observed operators adapting quickly as Microsoft blocked Internet-sourced VBA macros by default.
The revived malware also introduced significant technical changes while preserving its role as an information stealer and malware delivery platform. Analysts documented a shift to 64-bit modules, stronger runtime obfuscation, updated loaders, and a move from older RSA-based protections to elliptic-curve cryptography with encrypted HTTP command-and-control traffic. Emotet continued harvesting host data, credentials, Outlook and Thunderbird email content, and Chrome-stored payment information, while restoring modules such as its SMB spreader to move laterally and using infected systems as spam bots. Multiple reports also linked Emotet to follow-on payload delivery including IcedID, QakBot, Cobalt Strike, SystemBC, XMRig, and ransomware-enabling access, underscoring its renewed position as a resilient initial-access and malware-as-a-service threat.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
61 events from the most recent confirmed update back to the earliest known activity.
On 2022-04-29, IronNet observed a thread-hijacking phishing email delivering a ZIP archive with an XLL file that downloaded an Emotet DLL from gla[.]ge to a targeted Asia-Pacific organization. The report assessed the activity as a likely MUMMY SPIDER/TA54 test of XLL or OneDrive-based delivery to bypass Microsoft's default macro blocking.
On 2022-04-22, Emotet spam campaigns used password-protected ZIP archives containing malicious LNK files that dropped a VBScript into the Temp directory, downloaded the payload from remote servers, and executed it with regsvr32.exe. The report described this LNK-plus-script delivery chain as a new Emotet technique compared with earlier Excel-based campaigns.
Bitsight observed Emotet using LNK files instead of its usual Excel files on April 22, 2022, indicating an effort to improve infection success rates.
Researchers observed Emotet Epoch 4 switch from primarily 32-bit code to 64-bit loaders and stealer modules as of about 14:00 UTC on 2022-04-18. Cryptolaemus said the change reduced detection rates by roughly 60% and had not yet been seen on Epoch 5 at the time of reporting.
By late April 2022, Emotet had corrected a broken shortcut-based installer and shifted to Windows shortcut files that directly executed PowerShell to download staged scripts and the DLL payload.
On 2022-03-23, Fortinet published analysis of a recent Emotet campaign showing the core DLL receiving fileless modules from C2, executing them via a thread-module that hollowed a copied certutil.exe process, and exfiltrating stolen data over HTTP POST. The three observed modules stole browser passwords with NirSoft WebBrowserPassView, harvested Outlook contact data, and stole email account settings and credentials with NirSoft Mail PassView.
Since March 2022, Bitsight observed Emotet targeting more than 3 million unique email addresses and stealing more than 300,000 unique email credentials.
By March 2022, Fortinet had captured more than 500 malicious Excel files used to deliver Emotet to 64-bit Windows systems through macros, VBS, batch files, and a DLL payload.
As of February 2022, researchers observed Emotet replacing rundll32.exe with regsvr32.exe /s for payload execution in recent campaigns.
On January 27, 2022, Unit 42 observed an active thread-hijacked Emotet lure email carrying a password-protected ZIP archive or Excel spreadsheet that initiated the new staged infection chain.
An analyzed Emotet Epoch 4 infection began around 19:37 UTC on January 20, 2022, using a spam-linked Excel file, mshta, JavaScript, PowerShell, and rundll32 to execute the downloaded DLL.
An analyzed Emotet Epoch 5 infection began around 17:46 UTC on January 20, 2022, after a victim clicked a spam link and downloaded a malicious Excel file that led to mshta, PowerShell, and a DLL payload.
On 2022-01-18, SANS analyzed an Emotet infection in which the compromised Windows host began spambot activity about 27 minutes after infection. The host issued DNS blacklist queries prefixed with 0.0.0.0 and used the SMTP command EHLO [0.0.0.0], a behavior highlighted as a useful indicator of Emotet-driven malicious email activity.
VMware NSX Sandbox detected multiple Emotet attack waves in January 2022 and the following weeks through March 1, 2022, collecting thousands of malicious documents and DLL payloads for analysis.
Unit 42 first observed a new Emotet infection chain on December 21, 2021, using Excel 4.0 macros to launch mshta and staged PowerShell that cycled through 14 URLs to fetch an Emotet DLL.
On 2021-11-30, Emotet started using Microsoft App Installer in a new infection chain, with complaint-themed emails linking to fake Google Drive-style pages on compromised websites. The malicious .appinstaller files fetched .appxbundle packages that ultimately downloaded and executed Emotet on vulnerable Windows 10 systems.
LAC confirmed that Emotet attack emails targeting organizations in Japan began arriving around November 17, 2021, shortly after the botnet's renewed activity resumed. The advisory said the observed campaigns used malicious macro-enabled Office documents and reply-chain style phishing emails.
A downloaded 32-bit Emotet DLL from the renewed late-2021 campaign appeared to have been compiled on November 16, 2021, though researchers noted the timestamp might not be fully reliable.
Multiple sources observed renewed Emotet activity beginning on November 15, 2021, including mass email campaigns and delivery via existing Trickbot infections, apparently aimed at rebuilding the botnet.
After Emotet's November 2021 return, Intel 471 reported the revived malware replaced RSA-based cryptography with ECC using ECDH and ECDSA, retained a three-layer protocol with modified command handling, and moved process enumeration out of the initial check-in into a dedicated module. The analysis also identified two botnets, Epoch4 and Epoch5, based on the new encryption keys.
After Emotet's return in November 2021, researchers observed the new version remained broadly similar to earlier variants but changed its command-and-control data and encryption and appeared to use HTTPS instead of plain HTTP for C2 communications.
Emotet resumed operations in November 2021 following the January 2021 takedown, restoring spam-driven distribution and botnet activity.
Unit 42's traffic examples showed domains such as obob[.]tv and fathekarim[.]com likely hosting Emotet DLL payloads on January 5, 2021, with one example followed by Trickbot activity.
By late January 2021, coordinated law-enforcement action had shut down Emotet infrastructure, ending the botnet's then-current operations.
In January 2021, an international law-enforcement operation involving multiple countries seized or disrupted Emotet infrastructure and redirected infected machines to law-enforcement-controlled systems.
Since December 21, 2020, the initial Emotet binary in observed infections has been a Windows DLL rather than a Windows EXE.
Netskope observed Emotet activity in October 2020 using PowerShell and WMI to download and execute its payload.
On September 3, 2020, a Windows 10 host was infected with Emotet, which exfiltrated legitimate email thread data at 16:34 UTC and sent a spoofed thread-hijacked reply with a malicious Word document at 18:22 UTC.
On July 17, 2020, the Emotet botnet resumed activity after a five-month pause. Researchers later built a dataset of 38,000 samples collected between July 17 and July 28.
By February 6, 2020, VirusTotal detection for the analyzed Emotet-downloaded executable had increased to 49 of 73 engines.
On January 21, 2020, VirusTotal detected an analyzed Emotet malicious Word document at 13 of 61 engines and its downloaded executable at 6 of 73 engines.
In January 2020, CISA warned of increasing targeted Emotet activity affecting government organizations, private organizations, and home users.
From 2019-11-05 to 2019-11-08, the same Emotet administrative share spreader hash was obtained from all three Emotet epochs on consecutive days.
Emotet Outlook mail harvester modules fetched on 2019-11-04 and 2019-11-05 differed only in a few bytes containing command-and-control addresses, showing operators were patching binaries without recompilation.
Timestamp clustering showed renewed Emotet module compilation activity in October 2019 after the summer lull.
An Emotet network password bruteforcer module was first submitted to VirusTotal on 2019-05-17.
An Emotet administrative share spreader module with a March 2019 compile timestamp was first submitted to VirusTotal on 2019-05-14.
In early May 2019, Fortinet investigated a new Emotet sample delivered by a malicious Word document and found a multi-stage loader, persistent payload named itsportal.exe, and 61 hard-coded command-and-control servers.
Since early April 2019, Proofpoint observed TA542 consistently distributing Emotet by replying to existing benign email conversations. The report linked this tactic shift to an email-stealing module first observed in October 2018 that harvested recent message content and addressing data.
At least six Emotet modules were compiled on 2019-03-31 within about two minutes, suggesting they were built from one Visual Studio solution.
Observed module compilation activity was absent during summer 2019, aligning with reports that Emotet paused operations from June until September 2019.
On April 14, 2018, Emotet resumed using GET requests with Cookie-header data transfer for payloads smaller than 1 KB while retaining POST for larger data.
In April 2018, Emotet acquired a Wi-Fi propagation module that attempted dictionary attacks against wireless networks and reported successful access to command-and-control servers.
In February 2018, the city of Allentown, Pennsylvania experienced a malware attack whose pattern Microsoft later said appeared to match the Emotet outbreak model, though this was not officially confirmed.
In January 2018, Emotet began distributing the Panda banking trojan, also known as Zeus Panda.
IBM X-Force reported in November 2017 that Emotet had been observed distributing the IcedID banking trojan.
In August 2017, Emotet incorporated Network Spreader as a DLL module and expanded its brute-force password list to exactly 1,000 entries.
In July 2017, Emotet updated its loader to stop using GET requests with Cookie-header data transfer and switched all command-and-control communication to POST requests.
Beginning June 1, 2017, Emotet distributed a Network Spreader tool that brute-forced passwords on network resources, copied a service executable, and created a remote service for persistence.
On 2017-05-09, FortiGuard Labs published analysis of a new Emotet variant's modules, including one that harvested Outlook PST email data and another that retrieved spam templates and recipient lists from C2 to send malicious emails over SMTP.
In May 2017, Emotet spam campaigns moved to malicious Office documents that prompted users to enable macros, which then launched PowerShell to download Emotet.
In late April 2017, Emotet spam campaigns began using PDF attachments that directed victims to download JavaScript payloads.
In April 2017, Emotet spam campaigns targeted users in Poland with fake DHL-themed JavaScript downloaders and British-German users with fake invoice-themed JavaScript downloaders.
In February 2017, researchers confirmed Emotet could send spam independently through a spam module downloaded from command-and-control servers.
A new Emotet modification was discovered in December 2016 using the RIG-E and RIG-V exploit kits for distribution. This version replaced RC4 with AES and adopted a modified Google Protocol Buffer-based C2 protocol.
Emotet command-and-control servers became unavailable again in June 2015, beginning a roughly 18-month pause in activity.
In 2015, Kaspersky documented Emotet sending malicious emails to addresses harvested from infected systems, including messages about invoices, payment details, and order information. The tactic showed Emotet using victims' own contact lists to improve social-engineering effectiveness.
A new Emotet variant appeared in early 2015 with a new built-in RSA key, encrypted strings, cleaned ATS scripts, and Swiss bank targets.
Emotet command-and-control servers stopped responding in December 2014, causing activity to decline significantly.
By November 2014, Emotet had added modules for HTTP(S) traffic modification, Outlook address harvesting, Mail PassView credential theft, spam sending, and DDoS organization. By late 2014 it was also using Automatic Transfer System techniques to steal funds automatically.
Trend Micro first discovered Emotet in late June 2014 as a banking trojan targeting German and Austrian bank customers using spam-delivered malicious attachments and links.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
checkpoint.com
Open sourcemaxkersten.nl
Open sourceintel471.com
Open sourcezscaler.com
Open sourceproofpoint.com
Open sourcecrowdstrike.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.