CSIDB logo
Organisation

Emotet botnet

Profile

Primary URL
Undetermined
Location
-
Sector
Technology
Known incidents
1 incident
Updated
2026-07-01 10:04
Aliases
2 aliases

Organisation tracking is available to eligible accounts.

Profile narrative

Emotet first emerged around 2014 as a banking Trojan designed to harvest online banking credentials from infected systems. Over the following years its developers shifted its focus from pure credential theft to a broader role as a malware distribution platform. The botnet is best known for conducting massive spam email campaigns that carry malicious Word documents or links leading to payload download. Recipients who enable macros or click the links unwittingly execute the Emotet loader, which then establishes contact with command‑and‑control servers. Once a foothold is secured, the malware can retrieve additional modules that extend its capabilities beyond banking fraud. This evolution has allowed Emotet to remain a persistent threat across multiple industries and geographic regions.

A core characteristic of Emotet is its modular design, which enables operators to swap out or update functional components without reinstalling the base infection. The malware employs polymorphic packing and encryption to alter its binary signature on each generation, hindering signature‑based detection. Infected machines are used to harvest credentials from browsers, email clients, and network resources, which are then reused or sold for further intrusion. Emotet has been observed delivering secondary payloads such as TrickBot, Ryuk ransomware, and various information stealers, effectively acting as a dropper for other criminal operations. The botnet’s infrastructure has been rented out on underground markets as a malware‑as‑a‑service offering, lowering the barrier for other threat actors to launch large‑scale campaigns. These technical and business model traits have contributed to Emotet’s reputation as one of the most versatile and resilient botnets observed in the wild.

On July 21, 2020, an unidentified actor gained access to Emotet’s distribution infrastructure and replaced the malicious payloads with memes and GIFs. This alteration prevented the botnet from delivering its usual malware, effectively blocking new infections for the duration of the compromise. The intrusion was facilitated by the reuse of previously stolen credentials that allowed the attacker to upload web shells to the compromised servers. Using those shells, the actor could swap content in real time, sometimes within minutes, ensuring that visitors received harmless media instead of harmful code. Although the original operators could potentially regain control by acquiring alternative servers or using backup infrastructure, the incident caused a noticeable interruption in Emotet’s activity. In the aftermath, some of the previously abused domains were observed redirecting users to online surveys rather than serving malicious content, indicating a lasting impact on the botnet’s reach.

Incidents

1 incident linked to this organisation.

CSIDB