Return of Emotet malware
ID: 2790eff8-e879-57b8-bfb2-b0c05b160bf3
STIX ID: report--2790eff8-e879-57b8-bfb2-b0c05b160bf3
Feed Name: Zscaler Security Research Blog
Threat Score
Emotet resurfaced in November 2021 after a law‑enforcement disruption earlier in the year; this report documents its return via TrickBot and reply‑chain email spam using .docm/.xlsm and passworded .zip attachments, notes changes such as HTTPS-based C2 and updated encryption, maps relevant MITRE ATT&CK techniques, and provides IOCs (sample hash, multiple C2 IPs/ports, public keys, and malicious URLs) for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
