logo

Emotet adds a further layer of camouflage

ID: 846c6e3c-2c8f-5516-9b41-6322c18fd31f

STIX ID: report--846c6e3c-2c8f-5516-9b41-6322c18fd31f

Feed Name: The Spamhaus Project

Threat Score
75/100

Date Published: 2019-03-27

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

This report describes Emotet’s continued evolution from a banking Trojan into a highly distributed, modular malware service: researchers observed ~47,000 infected hosts emitting ~6,000 distinct malicious URLs (about 45% of observed distribution URLs), and noted recent evasive advances including RFC-compliant HTTP headers that mimic legitimate traffic and randomized URIs—changes that reduce the effectiveness of static network signatures and increase detection difficulty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.