Emotet
MITRE ATT&CK: S0367 View on attack.mitre.org
Aliases: Geodo, Heodo, Emotet
- First seen
- 2014-06-01 00:00:00
- Malware type
- botnet, downloader, trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 73425 (54778 malicious)
- Last IoC activity
- 2026-09-02 04:15:44
- Profile updated
- 2026-07-07 12:38:31
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical education-and-nonprofits technology-and-telecommunications
Context
Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.
Recent IoC activity
54,780 malicious indicators in Maltiverse are attributed to Emotet (S0367). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | d2b75040c3c43cc53e3cef1b5ae7b636e0076e9d1bec424dee69ed47b4ac33c5 | 2026-09-03 | 1 |
| file sample | WSoRfkK.exe | 2026-09-03 | 1 |
| hostname | kyleriffic.com | 2026-09-03 | 2 |
| hostname | www.esuefa.com | 2026-09-03 | 2 |
| hostname | www.tatweeralsham.com | 2026-09-03 | 1 |
| hostname | www.hineniestetica.com.br | 2026-09-03 | 3 |
| hostname | coach.getfit21latino.com | 2026-09-03 | 1 |
| hostname | m24news.com | 2026-09-03 | 1 |
| hostname | www.idgnet.nl | 2026-09-03 | 2 |
| hostname | cdaonline.com.ar | 2026-09-03 | 4 |
| hostname | tempnature.es | 2026-09-03 | 3 |
| hostname | stinkfinger.nl | 2026-09-03 | 3 |
| hostname | devinduncan.com | 2026-09-03 | 3 |
| hostname | ciadasluvas.com.br | 2026-09-03 | 2 |
| hostname | test2.cxyw.net | 2026-09-03 | 3 |
| hostname | tubbzmix.com | 2026-09-03 | 6 |
| hostname | www.anigamiparc.cat | 2026-09-03 | 3 |
| hostname | miris.in | 2026-09-03 | 2 |
| hostname | polandpresents.info | 2026-09-03 | 3 |
| hostname | zmgmedia.com | 2026-09-03 | 3 |
Detection coverage
- 9 YARA rules
- 831 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Credentials In Files (attack-pattern)
- Password Guessing (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Non-Standard Port (attack-pattern)
- Binary Padding (attack-pattern)
- Regsvr32 (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Malicious File (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Local Accounts (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Spearphishing Link (attack-pattern)
- Standard Encoding (attack-pattern)
- Network Share Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Embedded Payloads (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Email Collection (attack-pattern)
- Scheduled Task (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
Detection rules
- TRELLIX_ARC_MALW_Emotet (yara-rule)
- ARKBIRD_SOLG_MAL_Emotet_Nov_2021_1 (yara-rule)
- EMBEERESEARCH_Win_Emotet_String_Patterns_Oct_2022 (yara-rule)
- SIGNATURE_BASE_MAL_Emotet_JS_Dropper_Oct19_1 (yara-rule)
- SIGNATURE_BASE_MAL_Emotet_Jan20_1 (yara-rule)
- SIGNATURE_BASE_MAL_Emotet_BKA_Quarantine_Apr21 (yara-rule)
- SIGNATURE_BASE_MAL_Emotet_BKA_Cleanup_Apr21 (yara-rule)
- CAPE_Emotetpacker (yara-rule)
- CAPE_Emotetloader (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- threatconnect.com — Research Roundup Activity On Previously Identified Apt33 Domains (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For February Mummy Spider (report)
- proofpoint.com — Threat Actor Profile Ta542 Banker Malware Distribution Service (report)
- proofpoint.com — Comprehensive Look Emotets Summer 2020 Return (report)
- secureworks.com — Gold Crestwood (report)
- slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
- proofpoint.com — Holiday Lull Not So Much (report)
- proofpoint.com — Q4 2020 Threat Report Quarterly Analysis Cybersecurity Trends Tactics And Themes (report)
- CrowdStrike — Report2021Gtr (report)
- CISA — Aa22 110A (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Microsoft — Microsoft Digital Defense Report 2020 September (report)
- ibm.ent.box.com — Hs5Pcayhbbhjvj8Di5Sqdpbbd88Tsh89 (report)
- resources.malwarebytes.com — 2020 State Of Malware Report (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- bsi.bund.de — Lagebericht2020 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- zdnet.com — The Malware That Usually Installs Ransomware And You Need To Remove Right Away (report)
External references
- mitre-attack — S0367
- Emotet
- Geodo
- Talos Emotet Jan 2019
- CIS Emotet Apr 2017
- CIS Emotet Dec 2018
- Red Canary Emotet Feb 2019
- ESET Emotet Nov 2018
- Secureworks Emotet Nov 2018
- Picus Emotet Dec 2018
- Trend Micro Banking Malware Jan 2019
- Kaspersky Emotet Jan 2019
- Malwarebytes Emotet Dec 2017
- Symantec Emotet Jul 2018
- Trend Micro Emotet Jan 2019
- US-CERT Emotet Jul 2018
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy