Overview
Emotet began as credential theft on compromised routers and grew into the most widely deployed loader in the world.\nIt arrived as a macro-enabled document, downloaded modules for spam propagation and credential harvesting, then leased the foothold to ransomware operators.\nIts takedown by international law enforcement in 2021, and later resurrection, showed how much of the ecosystem depended on it.
Indicators of Compromise
Signals that suggest this is present on a system.
- Macro-enabled documents downloading a DLL
- PowerShell retrieving payloads from compromised WordPress sites
- Mail threads reused to lend legitimacy to new spam