EMOTET
EMOTET
BOTNET
MEALYBUG / TA54
Threat IntelligenceMalwareAugust 22, 202515 min read

Emotet: Threat Intelligence Profile

Modular botnet and loader

Scroll

Emotet (also known as Emotet, Heodo, Geodo) is a botnet active since 2014. Modular botnet and loader. Key characteristics include: modular loader, spam distribution, sold access to Conti/Ryuk, takedown Jan 2021, revived Nov 2021, re-disrupted 2023.

Overview & Background

Modular botnet and loader. First identified in 2014, this threat is attributed to Mealybug / TA542.

Threat Assessment

Emotet remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this botnet.

Technical Analysis

Emotet employs the following capabilities and techniques:

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentCommon delivery vector
ExecutionT1204.002 Malicious FileUser-triggered execution
PersistenceT1547.001 Registry Run KeysAutostart persistence
Defense EvasionT1027 Obfuscated FilesPayload obfuscation
C2T1071.001 Web ProtocolsHTTP/HTTPS C2

Detection & Defense

Defend Against Emotet

Mjolnir Security provides detection and response capabilities against Emotet and similar threats.

Threat DetectionIncident ResponseThreat HuntingMDR ServicesThreat Intelligence
  • Proactive Threat Hunting Hunt for Emotet indicators and TTPs within your environment.
  • Threat Intelligence Monitor Emotet campaigns and infrastructure changes.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: August 22, 2025