Netskope Threat Labs

Emotet

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Emotet is one of the most relevant botnets in the cyber threat landscape, and it evolved from a banking trojan into the premier malware loader for organized crime. It spreads through spam emails with malicious documents and password protected attachments, and it downloads payloads such as TrickBot, IcedID, and ransomware onto infected systems. An international takedown disrupted it in early 2021, but rebuilt infrastructure returned the botnet to service as a for hire delivery platform.

First seen
January 2022
Last seen
October 2026
EmoDldrEmoooDldrEmooodldrEmotet0s1EmotetABEmotetAEEmotetBEmotetCEmotetCryptEmotetDldrEmotetKEmotetLEmotetNEmotetPackerEmotetQuEmotetUEmotetcryptRemoteTemplInjRemoteTemplateInj

47 techniques across 10 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

TA0008 Lateral Movement

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel
Alert Name
Binary.Trojan.Emotet
DeepScan:Generic.Emotet.AD.DAC7784B
DeepScan:Generic.Emotet.ZZ.6696EA11
DeepScan:Generic.EmotetB.7FA684F6
DeepScan:Generic.EmotetB.CE17917C
DeepScan:Generic.EmotetB.D660415F
DeepScan:Generic.EmotetB.E2588697
DeepScan:Generic.EmotetC.023E744F
DeepScan:Generic.EmotetC.0D696A2D
DeepScan:Generic.EmotetC.A704FA48