Emotet remained a major malware delivery platform even after international authorities disrupted its botnet infrastructure, with investigators linking it to infections on roughly 1.6 million systems and to follow-on malware including TrickBot, IcedID, AZORult, and ransomware. Security research described a resilient, modular architecture in which a loader decrypted in-memory DLL modules for spamming, credential theft, Outlook harvesting, and proxying, while operators maintained parallel command-and-control infrastructures and rotated keys to complicate tracking. Campaigns commonly began with phishing emails, hijacked threads, or themed lures such as COVID-19 notices, invoices, jobs, and shipping messages, then used obfuscated Office documents, PowerShell, and rundll32.exe to install persistence, move payloads into randomized paths, and exfiltrate data over encrypted web traffic.
After the 2021 law-enforcement action, Emotet re-emerged with updated tooling and repeatedly changed its initial access methods to preserve infection rates. Researchers observed new loaders that decrypted embedded payloads directly, stronger obfuscation, possible movement from HTTP to HTTPS using cryptographic libraries, and continued runtime unpacking that hindered static detection. The operators also adapted to Microsoft’s macro restrictions by testing XLL files, then shifting from Word attachments to OneNote, WSF, VBScript, and later JavaScript downloaders delivered through ZIP archives or cloud-storage links. Additional telemetry showed ongoing changes in bot behavior, including altered spambot SMTP formatting, underscoring that Emotet’s operators continued to refine both malware internals and large-scale email distribution tactics.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
On March 16, 2023, Emotet changed its delivery method to malicious OneNote attachments. The OneNote infection chains used embedded WSF, VBScript, and later JavaScript downloaders to fetch and execute Emotet.
Talos reported that Emotet resumed spam-based malware distribution on March 7, 2023. The initial campaign used ZIP archives containing heavily padded Word documents with malicious VBA macros.
A December 2022 malware-analysis write-up documented extracting an Emotet core DLL from memory, reconstructing its API hash resolver, and recovering runtime-decrypted strings. The analyzed sample hash was fc345d151b44639631fc6b88a979462dfba3aa5c281ee3a526c550359268c694.
Proofpoint observed a pause in widespread Emotet activity between April 4 and April 19, 2022. During this lull, the actor appeared to test alternative low-volume delivery methods.
During an Emotet infection observed on 2022-01-24, the malware stopped using 0.0.0.0 in SMTP traffic and instead used the infected host's IP address with octets reversed. DNS blocklist-check queries still used the IP in normal order.
Deep Instinct reported that Emotet resurfaced roughly 10 months after the January 2021 takedown. The new loader retained heavy obfuscation and suggested a possible shift in communications from HTTP to HTTPS.
After taking control of Emotet infrastructure, law enforcement scheduled malware uninstallation from infected systems for April 25. This was cited later as part of the January disruption operation.
Investigators identified approximately 1.6 million computers worldwide infected with Emotet between April 1, 2020 and January 17, 2021, including more than 45,000 in the United States. The findings were cited in the later Justice Department announcement.
Multiple international law enforcement agencies took down Emotet infrastructure in January 2021. Authorities gained control of servers and replaced server-side malware with a law-enforcement-created file to sever infected systems from the botnet.
Unit 42 analyzed an updated Emotet campaign active since December 2020. The infection chain used phishing Word documents with obfuscated macros, PowerShell downloaders, staged DLL execution, persistence via Windows services, and encrypted HTTP C2 traffic.
Seqrite reported that Emotet resumed activity in September 2020 after an approximately five-month break. The renewed campaigns used hijacked email threads and lures themed around COVID-19, invoices, jobs, cyberattacks, and shipping.
Trend Micro observed Emotet Group 1 delivering TrickBot with gtag arz1 on September 20, 2018, followed by Group 2 on September 21, 2018. This supported the assessment that both infrastructures served similar purposes.
Analysis of 2018 samples found Emotet operating at least two parallel infrastructures with separate RSA key groups and non-overlapping command-and-control servers. Researchers concluded the design likely improved resilience and hindered tracking.
Trend Micro collected Emotet URLs, document droppers, and executables between June 1 and September 15, 2018 for a large infrastructure analysis. The dataset included 8,528 URLs, 5,849 document droppers, and 571 executables.
A school district in the Middle District of North Carolina was infected with Emotet in 2017. The infection disabled its network for about two weeks and caused more than $1.4 million in losses.
In 2017, Emotet changed from a banking Trojan into a platform for distributing third-party malware. Reported secondary payloads included TrickBot, Ryuk, Panda Banker, IcedID, and AZORult.
Trend Micro originally discovered Emotet as a banking Trojan in 2014. Later reporting also describes the botnet as active since at least 2014.
After the April 2022 pause, Proofpoint reported that Emotet resumed its usual high-volume email campaigns. The actor had also shown interest in infection methods that did not rely on macro-enabled documents.
Proofpoint identified a low-volume Emotet campaign using compromised sender accounts, minimalist emails with OneDrive links, and ZIP archives containing XLL files. The activity was attributed with high confidence to TA542 and assessed as testing new delivery techniques.
Deep Instinct released DeMotet, a public static unpacker for recent Emotet loaders. The tool extracts encrypted payloads and reveals hidden strings and API calls without executing the malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcekienmanowar.wordpress.com
Open sourceproofpoint.com
Open sourceisc.sans.edu
Open sourceseqrite.com
Open sourcetelekom.com
Open sourceus-cert.gov
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.