Emotet back in action after short break
ID: 0baeb4ff-4948-573c-9a75-8f19d446395c
STIX ID: report--0baeb4ff-4948-573c-9a75-8f19d446395c
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report analyzes the resurgence of the Emotet campaign after a two-month break, documenting new maldoc templates, three new RSA keys and reorganized C2/botnet infrastructure, the JavaScript downloader behavior, sample artifacts (MD5 and RSA key), embedded download URLs, and a long list of C2 IP:port indicators; it highlights Emotet’s modular role delivering additional threats (e.g., TrickBot, Ryuk) and provides IOCs to support network and endpoint detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
