Loader

Emotet

First seen: 2014-06 • Status: active

Currently Active Threat

Emotet is the 'malware delivery service' of the criminal world. It arrives via email, infects your computer, and then installs other malware - including ransomware. Despite being 'killed' multiple times by law enforcement, it keeps coming back. It's particularly dangerous because it hijacks real email conversations to spread.

Overview

Emotet is one of the most dangerous and persistent malware families in history. Originally a banking trojan, it evolved into a malware distribution platform that delivers other threats including ransomware. Despite multiple takedowns, Emotet has repeatedly resurfaced.

Also Known As

Heodo, Geodo

How It Spreads

  • Phishing emails with malicious Office attachments
  • Email thread hijacking (replies to real conversations)
  • Malicious links in emails
  • Infected Office documents with macros
  • Compromised email accounts spreading to contacts

What It Does

  • Installs additional malware (ransomware, banking trojans)
  • Steals email credentials and address books
  • Sends spam from infected machines
  • Creates persistence for other threats
  • Moves laterally through networks
  • Harvests network and system information

Is your business exposed?

Target Platforms

Windows 7, Windows 10, Windows 11

Detection Tips

  • Block Office macros from internet-downloaded documents
  • Monitor for suspicious PowerShell and WScript execution
  • Alert on SMTP traffic from non-email servers
  • Watch for processes creating scheduled tasks
  • Detect unusual DLL loading patterns

MITRE ATT&CK Techniques

T1566, T1059, T1204, T1105, T1021

If You're Infected

  1. 1.

    Isolate infected systems immediately

  2. 2.

    Assume email credentials are compromised - reset passwords

  3. 3.

    Check for other malware - Emotet often brings friends

    Multiple AV scanners

  4. 4.

    Review email logs for spam sent from your accounts

  5. 5.

    Alert contacts that may have received malicious emails from you

  6. 6.

    Block Office macros by policy going forward

Related Malware

Trickbot, Qakbot, Icedid

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required