logo

Return of Emotet malware

ID: 2790eff8-e879-57b8-bfb2-b0c05b160bf3

STIX ID: report--2790eff8-e879-57b8-bfb2-b0c05b160bf3

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Emotet resurfaced in November 2021 after a law‑enforcement disruption earlier in the year; this report documents its return via TrickBot and reply‑chain email spam using .docm/.xlsm and passworded .zip attachments, notes changes such as HTTPS-based C2 and updated encryption, maps relevant MITRE ATT&CK techniques, and provides IOCs (sample hash, multiple C2 IPs/ports, public keys, and malicious URLs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.