Emotet developed from a banking trojan targeting German, Austrian, and later Swiss banks into a modular malware platform used for credential theft, spam propagation, and follow-on intrusion activity. Early and mid-stage variants were commonly delivered through phishing emails, malicious links, macro-enabled Office files, or JavaScript downloaders, then established persistence, injected into processes, harvested host and email data, and communicated with hard-coded or encrypted command-and-control infrastructure using protected configurations and encrypted traffic. Researchers documented repeated anti-analysis upgrades, including debugger and sandbox checks, abuse of the Windows CreateTimerQueueTimer API, fake or obfuscated C2 data, and repeated self-updates designed to frustrate reverse engineering.
Later Emotet campaigns added stronger camouflage on both the wire and in the binary, with more RFC-compliant HTTP traffic, randomized URIs, and a redesigned configuration scheme that split obfuscated C2 addresses across multiple functions instead of storing a single encrypted blob. Incident responders also observed Emotet acting as an initial access broker: in one enterprise intrusion, a phishing-delivered Excel file installed Emotet, which spread via email, then downloaded Cobalt Strike and enabled credential dumping, Kerberoasting, lateral movement, remote-access tool deployment, and data exfiltration with Rclone to MEGA, stopping only before likely ransomware deployment. The reporting shows Emotet’s progression from banking malware into a resilient access-and-delivery ecosystem that supports broader post-compromise operations, including combinations with threats such as Trickbot and Ryuk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Since mid-May 2022, newer Emotet samples stopped storing the encrypted command-and-control configuration as a single blob in the PE .data section and instead distributed obfuscated IP-and-port data across multiple functions. VMware said this change complicated static extraction of Emotet infrastructure and reflected ongoing internal refactoring.
During the same May 2022 intrusion, the attackers installed Atera and Splashtop for persistence and remote access, then used Rclone to exfiltrate sensitive data from SMB shares to MEGA. The report notes the same data was exfiltrated twice from two different hosts.
Around 29 hours into the May 2022 intrusion, the attackers began SMB-based lateral movement using a transferred Cobalt Strike DLL and remote services, including Pass-the-Hash activity. At roughly 31 hours, they pivoted to the domain controller and elevated privileges with Cobalt Strike Get-System.
Roughly 26 hours after the initial May 2022 infection, Emotet downloaded and executed a Cobalt Strike payload on the beachhead host. The beacon was injected into svchost.exe and dllhost.exe and used HTTP traffic to a command-and-control server at 59.95.98.204:8080.
About 40 minutes after the May 2022 infection, Emotet began sending malicious XLS and ZIP attachments using compromised email accounts from the victim environment. This showed Emotet acting as both an initial access malware and a concurrent spam bot.
In May 2022, a phishing email carrying a ZIP archive with the malicious Excel file info_1805.xls led a user to enable macros, download hvxda.ocx, and execute it with regsvr32.exe. The payload was an Emotet DLL that established persistence, performed host discovery, and contacted command-and-control infrastructure.
On 2020-12-09, Netskope detected multiple novel Emotet Office-document samples that hid malicious XSL scripts in VBA control properties and executed them through a Squiblytwo-style wmic.exe chain. The report also disclosed new evasion details and indicators of compromise, including runtime string construction, WMI-based process creation, dropped DLLs, and command-and-control domains and URLs.
In 2017, Symantec observed Mealybug using Emotet to deliver other payloads, including the IcedID banking Trojan, TrickBot, and UmbreCrypt ransomware. The report characterized this as a shift from Emotet's original banking focus toward operating as a malware delivery service for other threat actors.
FortiGuard Labs captured an obfuscated JavaScript downloader delivering a new Emotet Trojan variant. The downloader fetched the payload from multiple URLs, saved it as a random executable, established Startup-folder persistence, and launched a replacement process.
Emotet resurfaced in January 2015 as a new modification referred to as version 3. The new version introduced a different embedded RSA public key and expanded targeting to Swiss banks alongside German and Austrian institutions.
Kaspersky reported that Emotet version 2 ceased activity in December 2014. The last recorded command from its command centers was sent on 2014-12-10 at 11:33:43 Moscow time.
Heise states that Trend Micro first reported on Emotet in June 2014 and coined the name Emotet. The first version, also called Geodo, was spread through spam posing as invoices or bank messages.
From autumn 2014, Emotet's second generation introduced a modular design in which a core component could download additional banking, spam, credential theft, Outlook harvesting, and DDoS modules. This expanded the malware beyond its original banking-trojan role.
A later Emotet variant discovered in autumn 2014 introduced Automatic Transfer System functionality to automate fraudulent transfers from victims' bank accounts. This marked a shift from credential theft to direct automated fraud.
Trend Micro reported detecting the Emotet banking Trojan in the summer of 2014. Early Emotet was described as malware that intercepted banking traffic to steal account details.
Spamhaus Malware Labs identified recent Emotet changes that made network traffic look more legitimate by aligning HTTP packets more closely with RFC conventions and adding randomized URIs. Over the prior two months, Spamhaus tracked about 47,000 infected machines and roughly 6,000 compromised-website URLs used as infection vectors.
Trend Micro observed a new Emotet variant that replaced RunPE with abuse of the Windows CreateTimerQueueTimer API to execute its payload. The same variant also added anti-analysis and anti-sandbox checks to avoid execution in research environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
thedfirreport.com
Open sourceblogs.vmware.com
Open sourcenetskope.com
Open sourceheise.de
Open sourcespamhaus.org
Open sourcesymantec-enterprise-blogs.security.com
Open sourceblog.trendmicro.com
Open sourceblog.fortinet.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.