logo

Emotet back in action after short break

ID: 0baeb4ff-4948-573c-9a75-8f19d446395c

STIX ID: report--0baeb4ff-4948-573c-9a75-8f19d446395c

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes the resurgence of the Emotet campaign after a two-month break, documenting new maldoc templates, three new RSA keys and reorganized C2/botnet infrastructure, the JavaScript downloader behavior, sample artifacts (MD5 and RSA key), embedded download URLs, and a long list of C2 IP:port indicators; it highlights Emotet’s modular role delivering additional threats (e.g., TrickBot, Ryuk) and provides IOCs to support network and endpoint detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.