Emotet Strikes Again, Resuming Spamming Operations
ID: a408c590-9040-5287-abc3-0605fd84ebce
STIX ID: report--a408c590-9040-5287-abc3-0605fd84ebce
Feed Name: Cyble Blog
**Executive summary:** The Emotet botnet resumed operations on March 7, 2023, distributing spam with ZIP attachments that contain oversized DOC files (ZIP-bombing) which prompt users to enable macros; those macros retrieve a >500MB Emotet DLL from listed URLs, install it under %LOCALAPPDATA% and execute it via regsvr32.exe, enabling C2 communication and delivery of secondary payloads. The report provides geographic campaign observations, IOCs (hashes, URLs), MITRE ATT&CK mappings, and recommended mitigations to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
