logo

Emotet Malware Returns: Malspammer Strikes Again

ID: 9b9f1a5a-9f25-5d9b-ae26-b31714c1ff4c

STIX ID: report--9b9f1a5a-9f25-5d9b-ae26-b31714c1ff4c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

### Executive Summary This report details an active Emotet malspam campaign (September 2020) that distributes malicious Office documents prompting users to enable macros; those macros invoke PowerShell to retrieve a packed Emotet payload which persists under %AppData% and communicates with remote C2 servers. The document provides infection-chain TTPs and extensive IOCs including file hashes, malicious URLs, domains and IP addresses to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.