Emotet Malware back in Action
ID: fad3882f-0d88-54b6-bf57-e96b42cce5ce
STIX ID: report--fad3882f-0d88-54b6-bf57-e96b42cce5ce
Feed Name: Cyble Blog
Cyble Research Labs reports Emotet’s resurgence in late 2021–2022, documenting phishing campaigns that deliver malicious Excel attachments (including password-protected ZIPs) which execute hidden macros to download and run Emotet DLLs via multiple infection chains (mshta→PowerShell→rundll32, WScript→VBS/BAT→PowerShell, regsvr32), notes upgrades such as ECC usage and Cobalt Strike deployment, and provides extensive IOCs (file hashes, download URLs, and C2 domains) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
