logo

The Malware-as-a-Service Emotet

ID: 477daf24-7c44-4873-90cb-a6898ce444cd

STIX ID: report--477daf24-7c44-4873-90cb-a6898ce444cd

Threat Score

80/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes Emotet’s origins and evolution from a banking trojan into a sophisticated malware‑as‑a‑service run by TA542, detailing its phishing-based infection vectors (malicious macros, thread‑hijacking, smishing and watering‑hole), modular architecture and C2 behavior, its use to distribute a wide range of secondary payloads including banking trojans and ransomware (e.g., TrickBot, QakBot, Ryuk/Conti), observed links with other criminal groups and recommendations for detection and monitoring (notably public IOC feeds).