logo

Recent Emotet Spam Campaign Utilizing New Tactics

ID: 7d08b3c6-bbef-5119-a1e7-4f02e3889fdb

STIX ID: report--7d08b3c6-bbef-5119-a1e7-4f02e3889fdb

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-24

Date Updated: 2026-07-17

...
...

Emotet has resumed activity and is distributing payloads through malicious OneNote attachments that embed obfuscated WSF scripts; when users interact with a fake OneNote page the script drops a .wsf file which downloads a DLL payload (size-checked) and executes it via regsvr32, establishing C2 communications. The report provides technical details of the delivery chain, deobfuscation, sample hashes, known payload URLs, MITRE ATT&CK mappings, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.