Emotet

MITRE ATT&CK: S0367 View on attack.mitre.org

Aliases: Geodo, Heodo, Emotet

First seen
2014-06-01 00:00:00
Malware type
botnet, downloader, trojan
Family
Malware family
Operating systems
windows
Related IoCs
73425 (54778 malicious)
Last IoC activity
2026-09-02 04:15:44
Profile updated
2026-07-07 12:38:31

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical education-and-nonprofits technology-and-telecommunications

Context

Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.

Recent IoC activity

54,780 malicious indicators in Maltiverse are attributed to Emotet (S0367). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample d2b75040c3c43cc53e3cef1b5ae7b636e0076e9d1bec424dee69ed47b4ac33c5 2026-09-03 1
file sample WSoRfkK.exe 2026-09-03 1
hostname kyleriffic.com 2026-09-03 2
hostname www.esuefa.com 2026-09-03 2
hostname www.tatweeralsham.com 2026-09-03 1
hostname www.hineniestetica.com.br 2026-09-03 3
hostname coach.getfit21latino.com 2026-09-03 1
hostname m24news.com 2026-09-03 1
hostname www.idgnet.nl 2026-09-03 2
hostname cdaonline.com.ar 2026-09-03 4
hostname tempnature.es 2026-09-03 3
hostname stinkfinger.nl 2026-09-03 3
hostname devinduncan.com 2026-09-03 3
hostname ciadasluvas.com.br 2026-09-03 2
hostname test2.cxyw.net 2026-09-03 3
hostname tubbzmix.com 2026-09-03 6
hostname www.anigamiparc.cat 2026-09-03 3
hostname miris.in 2026-09-03 2
hostname polandpresents.info 2026-09-03 3
hostname zmgmedia.com 2026-09-03 3

Detection coverage

  • 9 YARA rules
  • 831 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Password Guessing (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Binary Padding (attack-pattern)
  • Regsvr32 (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Malicious File (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Local Accounts (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Email Collection (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_MALW_Emotet (yara-rule)
  • ARKBIRD_SOLG_MAL_Emotet_Nov_2021_1 (yara-rule)
  • EMBEERESEARCH_Win_Emotet_String_Patterns_Oct_2022 (yara-rule)
  • SIGNATURE_BASE_MAL_Emotet_JS_Dropper_Oct19_1 (yara-rule)
  • SIGNATURE_BASE_MAL_Emotet_Jan20_1 (yara-rule)
  • SIGNATURE_BASE_MAL_Emotet_BKA_Quarantine_Apr21 (yara-rule)
  • SIGNATURE_BASE_MAL_Emotet_BKA_Cleanup_Apr21 (yara-rule)
  • CAPE_Emotetpacker (yara-rule)
  • CAPE_Emotetloader (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • threatconnect.com — Research Roundup Activity On Previously Identified Apt33 Domains (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • CrowdStrike — Meet Crowdstrikes Adversary Of The Month For February Mummy Spider (report)
  • proofpoint.com — Threat Actor Profile Ta542 Banker Malware Distribution Service (report)
  • proofpoint.com — Comprehensive Look Emotets Summer 2020 Return (report)
  • secureworks.com — Gold Crestwood (report)
  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • proofpoint.com — Holiday Lull Not So Much (report)
  • proofpoint.com — Q4 2020 Threat Report Quarterly Analysis Cybersecurity Trends Tactics And Themes (report)
  • CrowdStrike — Report2021Gtr (report)
  • CISA — Aa22 110A (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Microsoft Digital Defense Report 2020 September (report)
  • ibm.ent.box.com — Hs5Pcayhbbhjvj8Di5Sqdpbbd88Tsh89 (report)
  • resources.malwarebytes.com — 2020 State Of Malware Report (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • bsi.bund.de — Lagebericht2020 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
  • Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
  • zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)

External references