Emotet Returns: New TTPs And .lnk File Attacks
ID: 6174dbfb-c52d-54ea-acb7-3d570d068578
STIX ID: report--6174dbfb-c52d-54ea-acb7-3d570d068578
Feed Name: Cyble Blog
Threat Score
This report details active Emotet spam campaigns (April 2024) that use zipped .lnk attachments to drop VBScript or PowerShell scripts which decode base64-encoded URLs and fetch Emotet payloads, executed via regsvr32. It presents two infection chains with SHA256 hashes, MD5/SHA1 mappings, multiple dropper URLs, execution-flow figures, MITRE ATT&CK technique mappings, and recommended defensive measures including patching, MFA, AV, and user caution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
