logo

Independence Day greeting campaign delivers Emotet

ID: 99e9e8f5-7df1-52d0-b6ba-87fbd09f0275

STIX ID: report--99e9e8f5-7df1-52d0-b6ba-87fbd09f0275

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabZ observed an active Emotet campaign (July 2–4) distributing malicious Microsoft Office "Greeting Card" attachments that prompt users to enable macros; an obfuscated VBA macro launches a heavily obfuscated PowerShell payload downloader which installs Emotet (copies to system32, creates mutex PEM). The report includes de-obfuscation details, attack TTPs, and comprehensive IOCs: document and executable MD5s, download URLs/domains, and numerous C2 IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.