Threat Intelligence Tarot
pentacles · 9
Criminal (Eastern European)
G0120
risk 4/5
The Delivery Service
Emotet / Mealybug
Mealybug · Gold Crestwood · TA542
Global enterpriseGovernmentHealthcareAnyone with an email address
Active since ~2014 (recurring) · Malware-as-a-service delivery, Banking credential theft, Ransomware loader
Emotet is the postal service of malware. It delivers whatever its clients need - TrickBot, Ryuk, Qbot, AnyDesk - to whatever inbox it can reach. At peak, 1.6 million machines waited for its instructions. When Europol took it down, the world exhaled. When it returned ten months later, the world understood: The Delivery Service has a second shift.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
T1566.001
Spearphishing Attachment
Initial Access
T1204.002
Malicious File
Execution
T1059.001
PowerShell
Execution
T1071.001
Web Protocols
Command and Control
T1583.005
Botnet Infrastructure
Resource Development
Notable Operations
  • World's largest malware botnet - 1.6M infected machines at peak
  • Europol/FBI global takedown operation (January 2021)
  • Resurrected by TrickBot operators in late 2021
  • NATO, UN, and US government targeting alongside global spam campaigns
Defenses
Reversed: Their Weakness
Emotet's January 2021 takedown by a coalition of 8 countries was historic - and the decision to use the botnet's own update mechanism to push a self-uninstall module to infected machines was unprecedented. Its return proved resilience, but also proved that such operations are possible.

Share this adversary profile

swipe to browse

Data sourced from MITRE ATT&CK. For educational purposes.