The Malware-as-a-Service Emotet
ID: 477daf24-7c44-4873-90cb-a6898ce444cd
STIX ID: report--477daf24-7c44-4873-90cb-a6898ce444cd
Threat Score
80/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes Emotet’s origins and evolution from a banking trojan into a sophisticated malware‑as‑a‑service run by TA542, detailing its phishing-based infection vectors (malicious macros, thread‑hijacking, smishing and watering‑hole), modular architecture and C2 behavior, its use to distribute a wide range of secondary payloads including banking trojans and ransomware (e.g., TrickBot, QakBot, Ryuk/Conti), observed links with other criminal groups and recommendations for detection and monitoring (notably public IOC feeds).
