logo

Emotet is back again: what does it mean?

ID: f1f362ee-aa47-584f-9b5d-74bd202211aa

STIX ID: report--f1f362ee-aa47-584f-9b5d-74bd202211aa

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2021-11-16

Date Updated: 2026-04-29

...
...

The report details Emotet’s resurgence after its takedown, noting the malware is rebuilding infrastructure (likely via TrickBot), leveraging stolen email chains and malspam to distribute Office/ZIP payloads and C2s, and is expected to be reused by ransomware and other cybercriminal operators; recommended defenses include email gateways, phishing awareness, macro restrictions, MFA, and monitoring for impersonating domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.