Emotet continued to evolve from a banking trojan into a resilient modular malware platform, using phishing and thread-hijacked emails to deliver malicious Office files, password-protected ZIP archives, oversized documents, OneNote attachments, and later .LNK shortcut files. Multiple analyses showed operators repeatedly changing initial access and execution methods: older campaigns relied on VBA or XLM macros, while later waves used embedded VBScript, JavaScript, and shortcut-based loaders to fetch DLL payloads from hard-coded URLs and execute them with LOLBins such as regsvr32.exe, rundll32.exe, wscript.exe, cmd.exe, PowerShell, and certutil.exe. Researchers also documented a shift from earlier "Project X" payloads to a newer "Project Y" core DLL, alongside continued use of thread hijacking and downloader chains designed to blend into normal Windows activity.
Technical reporting showed Emotet actively bypassing common defenses and maintaining a mature post-infection capability set. One Word-document sample used WMI so that cmd.exe was spawned by WmiPrvSe.exe instead of directly by Word, sidestepping Microsoft Defender's Office child-process Attack Surface Reduction rule; another macro deobfuscated strings, launched WMI-backed process creation, and ran a base64-encoded PowerShell downloader. Across samples, the malware established persistence through Registry Run keys or Windows services depending on privilege level, used process hollowing, browser credential theft modules, encrypted command-and-control with embedded RSA/AES or ECC-based protections, and rotated hard-coded C2 infrastructure. Defenders were advised to block password-protected archives and macro-enabled documents where possible, hunt for WMI-originated process creation, and monitor for suspicious use of regsvr32.exe, rundll32.exe, and other LOLBins tied to Emotet delivery chains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
In its March 2023 resurgence, Emotet used heavily padded Microsoft Word documents with malicious macros as an initial infection vector.
Trellix reported that Emotet resumed operations in March 2023 after a short break, continuing activity with epoch 4 and epoch 5 variants.
Later in 2023, Emotet moved from malicious Word documents to Microsoft OneNote files with embedded VBScript or JavaScript after Microsoft blocked macros by default in internet-downloaded Office files.
Around April 22, 2022, Emotet operators changed tactics to use malicious Windows shortcut files that extracted embedded VBScript, downloaded a DLL from one of seven URLs, and executed it with regsvr32.
Researchers observed a new Emotet campaign on February 21, 2022 that introduced a new core payload called Y.dll, referred to as Project Y, delivered via password-protected ZIP files containing malicious Excel documents.
Trellix reported that after returning in late 2021, Emotet increased its operations during 2022.
By January 2022, researchers observed Emotet spam campaigns using malicious Excel 4.0 macro documents that launched cmd.exe and mshta.exe to fetch HTA payloads from URLs containing hexadecimal or octal IP address formats. The technique was assessed as an evasion method against pattern-based detection because operating systems normalized the nonstandard IPs into standard dotted-decimal addresses.
By December 15, 2021, Emotet had started deploying Cobalt Strike beacons on compromised hosts, expanding its post-infection tooling.
Emotet resumed operations on November 15, 2021, marking its return after the January 2021 botnet disruption.
Analysis of a January 2021 Emotet Word document showed its VBA macro launching cmd.exe through WMI so the parent process became WmiPrvSe.exe, bypassing the Defender ASR rule meant to block Office child processes.
Law enforcement agencies carried out a major disruption of Emotet infrastructure in January 2021, including a Europol-backed takedown effort.
An Emotet email campaign using malicious zipped documents was observed around 20 December 2020, including Italian-language phishing emails in the analyzed case.
A new Emotet version was observed around mid-September 2019, and researchers found three new RSA keys replacing the two previously seen botnets, indicating infrastructure reorganization into new Epochs.
Around the end of August 2019, Emotet command-and-control servers came back online following the earlier operational pause.
Emotet activity paused for about two months after its command-and-control servers went down in late May 2019.
A malicious Word document received on February 1, 2019 used VBA macros to launch a hidden PowerShell downloader that iterated through multiple URLs, saved a payload as C:\windows\temp\putty.exe, and executed it. Analysis of a misconfigured delivery site also exposed server-side PHP used to decode and serve the Emotet payload while tracking victim operating-system statistics.
Check Point reported that Emotet's original banking module was removed at some point in 2017, reflecting its shift toward modular downloader and botnet operations.
Emotet first appeared in 2014 as a banking trojan targeting financial institutions before later evolving into a broader malware delivery platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcecynet.com
Open sourcezscaler.com
Open sourcemaxkersten.nl
Open sourceblog.vincss.net
Open sourcegithub.com
Open sourceisc.sans.edu
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.