logo

Emotet Wi-Fi Spreader Upgraded

ID: e3c99b82-c007-55d2-ae03-e35aeee794ab

STIX ID: report--e3c99b82-c007-55d2-ae03-e35aeee794ab

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense observed an updated Emotet Wi‑Fi spreader that was transformed from a stand‑alone program into a module of Emotet: it now downloads a service binary and the Emotet loader from hardcoded C2s, adds verbose debug logging via a PHP POST protocol (sending MachineGUID as "id" and base64 debug strings as "data" to gate.php), and attempts SMB brute‑forcing of C$/ADMIN$ to propagate. The report includes technical details of the spreader and Service.exe behavior, notable artifacts hinting at development history, IOCs (hashes, URLs, drop paths), a YARA detection rule, and a Suricata rule for network detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.