logo

Emotet Evolves With new Wi-Fi Spreader

ID: 1807a6ec-fd7d-5f63-849e-79ab257ef5a9

STIX ID: report--1807a6ec-fd7d-5f63-849e-79ab257ef5a9

Feed Name: Binary Defense Blog

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This report analyzes an Emotet loader variant that enumerates local Wi‑Fi networks using wlanAPI, brute‑forces Wi‑Fi and SMB credentials to pivot across networks, drops a service (service.exe) and executes the Emotet payload; it documents worm.exe and service.exe behaviors, hard‑coded C2s and URIs (e.g., 87.106.37.146:8080 and 45.79.223.161:443), and provides YARA and Suricata detection signatures along with mitigation recommendations (strong Wi‑Fi passwords, monitor for new services and processes in temp/profile folders).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.