Emotet grew from a banking trojan into one of the most widely used malware delivery platforms, spreading mainly through phishing emails, hijacked reply chains, malicious Word and Excel attachments, and links that launched multi-stage infection chains. Researchers and government agencies reported that the malware stole email content, contacts, browser and mail credentials, and even reused stolen attachments to make lures more convincing, while also moving laterally inside Windows networks and maintaining persistence through services, registry changes, and in-memory modules. Campaigns increasingly abused legitimate tools such as mshta.exe, cmd.exe, PowerShell, rundll32.exe, and even process hollowing of renamed certutil.exe to evade detection.
The botnet became a critical initial access source for follow-on malware and ransomware, delivering payloads including TrickBot, QakBot, Dridex, IcedID, Gootkit, Ryuk, Conti, ProLock, and BitPaymer, prompting defenders to treat any Emotet infection as an urgent enterprise incident. An international law-enforcement operation in 2021 seized and sinkholed Emotet infrastructure and enabled victim notification and malware removal efforts, but the malware resurfaced later with updated tradecraft, including revised cryptography based on ECDH/ECDSA, newer Windows crypto APIs, stronger obfuscation, and renewed spam campaigns using malicious Excel files and macros. Security groups such as Cryptolaemus, national CERTs, and vendors continued publishing indicators and response guidance as organizations remained exposed to credential theft, secondary payloads, and ransomware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
27 events from the most recent confirmed update back to the earliest known activity.
Unit 42 described an Emotet email sent on January 27, 2022 that reused a stolen email thread from June 2021 and delivered a password-protected ZIP containing a malicious Excel file.
VMware reported that a recent Emotet attack wave affecting some customers in the EMEA region began on January 11, 2022, using malicious Excel attachments and PowerShell-based delivery.
FortiGuard Labs captured more than 500 malicious Microsoft Excel files in a 2022 Emotet campaign that delivered fileless modules for browser credential theft and email data theft.
Palo Alto Networks Unit 42 discovered on 2021-12-21 a new Emotet infection chain using malicious Excel files with obfuscated Excel 4.0 macros, mshta, and staged PowerShell.
Emotet resumed operations in mid-November 2021 after nearly 10 months of disruption, returning to large-scale malicious spam distribution.
Analysis of post-resurgence Emotet samples showed that newer binaries used elliptic-curve cryptography and Microsoft's CNG/BCrypt APIs instead of the older RSA-based design.
On 2021-02-19, Japan's Ministry of Internal Affairs and Communication, National Police Agency, ICT-ISAC, and ISPs announced a joint effort to notify users affected by Emotet.
Starting on 2021-02-05, JPCERT/CC received computer names for infected devices in Japan, improving its estimate of remaining Emotet infections.
As of 2021-01-27, about 900 IP addresses in Japan were observed connecting to Emotet infrastructure following the international disruption operation.
On 2021-01-27, an international law enforcement operation coordinated by Europol and Eurojust disrupted Emotet, seized control of its infrastructure, and sinkholed victim traffic.
Using reports collected from July 17 through September 3, 2020, Deep Instinct estimated that approximately 444,000 unique Emotet loaders were generated during the renewed wave.
From August 2020, France's public and private sectors were targeted by Emotet phishing campaigns using thread hijacking, according to ANSSI.
Emotet resumed sending large volumes of malicious spam on July 17, 2020, after more than five months of inactivity.
After returning in July 2020, Emotet initially installed TrickBot on compromised systems and later switched to heavily spreading QakBot instead.
Researchers said Emotet added an attachment-stealing module around June 13, 2020, enabling it to steal small attachments, email content, and contact lists for use in reply-chain phishing.
JPCERT/CC reported a growing number of Emotet infection cases in Japan starting in October 2019 and issued guidance on detection and response.
Deep Instinct said a previous Emotet wave began in September 2019 and ended in February 2020 before the botnet went quiet for several months.
Minerva Labs first observed Emotet using hijacked email conversation threads in March 2019 to make phishing messages appear more legitimate.
SANS documented Emotet infection chains observed on 2019-01-15 in which Emotet delivered secondary malware, including Gootkit in one case and IcedID in another.
Three major malspam campaigns, including Emotet, stopped sending malspam during the week ending 2018-12-23.
The idea for Cryptolaemus emerged in June 2018 in a Twitter group chat, leading researchers and administrators to organize a dedicated effort to track Emotet and publish indicators of compromise.
Joseph Roosen said his network was infected with Emotet in November 2017, and that VLAN segmentation helped contain the malware's lateral movement.
Trend Micro observed increased activity from new Emotet variants in August 2017, including samples that targeted sectors beyond banking and could deliver additional payloads such as Dridex.
During 2016 and 2017, Emotet replaced much of its codebase and evolved into a loader that delivered additional malware and rented access to infected systems to other criminal groups.
In 2016, Emotet began moving away from pure banking fraud as banks improved anti-fraud controls, starting its transition toward a broader malware delivery role.
Trend Micro first detected Emotet in 2014, when it operated as a banking trojan focused on stealing banking credentials and funds from victims.
A remover distributed through Emotet during the takedown was scheduled to uninstall the malware on 2021-04-25 by deleting its registry key and service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcethreatpost.com
Open sourceblogs.vmware.com
Open sourcevmray.com
Open sourceblog.trendmicro.com
Open sourcesymantec.com
Open sourceblog.trendmicro.com
Open sourcecert.ssi.gouv.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.