Loader
Emotet
First seen: 2014-06 • Status: active
Currently Active Threat
Emotet is the 'malware delivery service' of the criminal world. It arrives via email, infects your computer, and then installs other malware - including ransomware. Despite being 'killed' multiple times by law enforcement, it keeps coming back. It's particularly dangerous because it hijacks real email conversations to spread.
Overview
Emotet is one of the most dangerous and persistent malware families in history. Originally a banking trojan, it evolved into a malware distribution platform that delivers other threats including ransomware. Despite multiple takedowns, Emotet has repeatedly resurfaced.
Also Known As
Heodo, Geodo
How It Spreads
- • Phishing emails with malicious Office attachments
- • Email thread hijacking (replies to real conversations)
- • Malicious links in emails
- • Infected Office documents with macros
- • Compromised email accounts spreading to contacts
What It Does
- • Installs additional malware (ransomware, banking trojans)
- • Steals email credentials and address books
- • Sends spam from infected machines
- • Creates persistence for other threats
- • Moves laterally through networks
- • Harvests network and system information
Is your business exposed?
Target Platforms
Windows 7, Windows 10, Windows 11
Detection Tips
- • Block Office macros from internet-downloaded documents
- • Monitor for suspicious PowerShell and WScript execution
- • Alert on SMTP traffic from non-email servers
- • Watch for processes creating scheduled tasks
- • Detect unusual DLL loading patterns
MITRE ATT&CK Techniques
T1566, T1059, T1204, T1105, T1021
If You're Infected
- 1.
Isolate infected systems immediately
- 2.
Assume email credentials are compromised - reset passwords
- 3.
Check for other malware - Emotet often brings friends
Multiple AV scanners
- 4.
Review email logs for spam sent from your accounts
- 5.
Alert contacts that may have received malicious emails from you
- 6.
Block Office macros by policy going forward
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required