[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/emotet-malware-summary-epoch-4-5/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/emotet-malware-summary-epoch-4-5/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Emotet Summary: November 2021 Through January 2022

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 17, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Emotet](https://unit42.paloaltonetworks.com/tag/emotet/)
  * [Macros](https://unit42.paloaltonetworks.com/tag/macros/)
  * [MealyBug](https://unit42.paloaltonetworks.com/tag/mealybug/)
  * [Mummy Spider](https://unit42.paloaltonetworks.com/tag/mummy-spider/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [TA542](https://unit42.paloaltonetworks.com/tag/ta542/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/emotet-malware-summary-epoch-4-5/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/emotet-malware-summary-epoch-4-5/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Emotet%20Summary:%20November%202021%20Through%20January%202022&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F&title=Emotet%20Summary:%20November%202021%20Through%20January%202022 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F&text=Emotet%20Summary:%20November%202021%20Through%20January%202022 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Emotet%20Summary:%20November%202021%20Through%20January%202022%20https%3A%2F%2Funit42.paloaltonetworks.com%2Femotet-malware-summary-epoch-4-5%2F "Share in Mastodon")

## Executive Summary

Emotet is one of the most prolific email-distributed malware families in our current threat landscape. Although a coordinated law enforcement effort shut down this malware in January 2021, Emotet resumed operations in November 2021. Since then, Emotet has returned to its status as a prominent threat.

This blog provides a background on Emotet, and it reviews activity from this malware family since its return in November 2021. The information covers changes in Emotet operations from its revival through the end of January 2022. These examples will provide a more comprehensive picture and better indicate the worldwide threat Emotet currently poses.

Palo Alto Networks customers are protected from Emotet with [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) or our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) and [Threat Prevention](https://www.paloaltonetworks.com/network-security/threat-prevention) subscriptions.

|---------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Primary Malware Discussed | [Emotet](https://unit42.paloaltonetworks.com/tag/Emotet/)                                                                                                                                    |
| Operating System Affected | Windows                                                                                                                                                                                      |
| Related Unit 42 Topics    | [Malware](https://unit42.paloaltonetworks.com/category/malware-2/), [macros](https://unit42.paloaltonetworks.com/tag/macros/), [phishing](https://unit42.paloaltonetworks.com/tag/phishing/) |

## Background on Emotet

Sometimes referred to as Geodo or Feodo, Emotet is Windows-based malware that first appeared in 2014 as a banking Trojan. Since then, Emotet has evolved into modular malware that performs various functions, including information stealing, spambot activity and loading other malware.

The threat actor behind Emotet is known through different designators, like [Mealybug](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/evolution-emotet-trojan-distributor), [MUMMY SPIDER](https://www.crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the-month-for-february-mummy-spider/) or [TA542](https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta542-banker-malware-distribution-service).

Emotet's primary method of distribution is through email.

Emotet is a prolific spammer. Emotet-infected computers often act as spambots, sending a dozen or more emails every minute that push more Emotet. This means thousands of Emotet emails can be sent by a single host every day. If hundreds of Emotet-infected hosts are active at any given time, this means hundreds of thousands of Emotet emails can be generated each day Emotet is actively spamming.

Emotet is evasive. Through a technique called hashbusting, Emotet generates different file hashes for malware distributed through its botnets. This ensures a malware sample's SHA256 hash [is different on each infected system](https://twitter.com/malwaretechblog/status/1251606958592757760). Emotet also uses obfuscated code in scripts used during its initial infection process.

Emotet is nimble. Its botnets frequently update IP addresses and TCP ports used for command and control (C2) communications. Emotet also frequently changes URLs hosting its malware, sometimes using dozens of different URLs each day.

Emails distributing Emotet contain malicious attachments, or they contain links to malicious files. These messages most often contain Microsoft Office files like Word documents or Excel spreadsheets. These Office documents contain malicious macro code. The code is designed to infect a vulnerable Windows host after a victim enables macros.

As it rose to prominence, Emotet began distributing other malware like [Gootkit](https://isc.sans.edu/forums/diary/Emotet+infections+and+followup+malware/24532/), [IcedID](https://www.malware-traffic-analysis.net/2019/01/18/index.html), [Qakbot](https://www.malware-traffic-analysis.net/2020/08/10/index.html) and [Trickbot](https://unit42.paloaltonetworks.com/unit42-malware-team-malspam-pushing-emotet-trickbot/).

By September 2019, Emotet's infrastructure was [running on three separate botnets](https://twitter.com/Cryptolaemus1/status/1174195815876894720). These botnets were designated by the security research team [Cryptolaemus](https://paste.cryptolaemus.com/about/) as epoch 1, epoch 2 and epoch 3. The epoch designators are often abbreviated as E1, E2 and E3.

By 2020, a significant portion of [malicious spam pushing Emotet used thread hijacking](https://unit42.paloaltonetworks.com/emotet-thread-hijacking/). Thread hijacking is a technique that utilizes legitimate messages stolen from infected computers' email clients. Emotet emails have frequently spoofed legitimate users and impersonated replies to these stolen emails.

Emotet occasionally takes a break from delivering malicious emails. [Emotet's longest absence](https://www.proofpoint.com/us/blog/threat-insight/comprehensive-look-emotets-summer-2020-return) from the threat landscape occurred in early February 2020 and lasted more than five months. Emotet resumed operations in mid-July 2020, and it quickly [surpassed other threats](https://www.proofpoint.com/us/blog/threat-insight/comprehensive-look-emotets-summer-2020-return) in sheer volume of malicious spam.

In January 2021, a collaborative effort by law enforcement agencies and other authorities [disrupted Emotet operations](https://www.europol.europa.eu/media-press/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action). This effectively stopped the threat actor, and Emotet disappeared from our threat landscape.

Approximately 10 months later, Emotet resumed operations in mid-November 2021.

## Visual Timeline

Figure 1 presents a timeline of Emotet operations from its return in mid-November 2021 through January 2022. The timeline highlights notable Emotet activity during the three month period covered in this blog.
![Timeline of Emotet operations from November 2021-January 2022: Nov 14 - new Emotet binary seen from Trickbot infection, Nov 15 - Emotet resumes spamming (emails have attachments), Nov. 23 - batch files noted during Emotet infection process, Nov. 30 - Emotet starts abusing App Installer protocol, Dec. 7 - start seeing Cobalt Strike from Emotet infections, Dec 21 - Emotet emails primarily use links to download initial Office document, start seeing new infection method with .hta files and PowerShell script, Dec. 25 - Emotet spamming stops, Jan. 11 - Emotet spamming resumes, Jan. 21 - Emotet emails back to using attachments instead of links.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image.jpeg) Figure 1. Timeline of Emotet operations from November 2021 through January 2022.

## Emotet in November 2021

On Sunday, Nov. 14, 2021, security researcher [Luca Ebach](https://cyber.wtf/author/lucaebach1/) discovered a new Emotet binary [delivered through a Trickbot infection](https://cyber.wtf/2021/11/15/guess-whos-back/). By Monday, Nov. 15, [the Emotet infrastructure had resumed normal operations](https://isc.sans.edu/diary/Emotet+Returns/28044) and began generating a large volume of malicious spam.

The new Emotet infrastructure is running on two separate botnets designated as epoch 4 and epoch 5. These designators are often abbreviated as E4 and E5.

On Nov. 15, malicious spam for Emotet had one of three types of attachments: a password-protected ZIP archive, a Word document or an Excel spreadsheet. This follows the same method we had typically seen with previous Emotet infections. Examples and more details can be found in my post, "[Emotet Returns](https://isc.sans.edu/diary/Emotet+Returns/28044)." See Figure 2 for a flow chart documenting the chain of events.
![Flow chart documenting the chain of events for Emotet infections seen on Monday, Nov. 15, 2021: thread hijacked email \> password-protected ZIP or Office document \> enable macros \> web traffic for Emotet DLL \> Emotet DLL \> Emotet C2 traffic](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-1.jpeg) Figure 2. Chain of events for Emotet infections seen on Monday, Nov. 15, 2021.

[Appendix A](#Appendix-A-Emotet-epoch-4-activity) lists indicators of compromise from an infection on Wednesday, Nov. 18.

By Monday, Nov. 23, a batch file was added to the infection process as shown below in Figure 3.
![Chain of events for Emotet infections seen Monday, Nov. 23, 2021: threat hijacked email \> password-protected ZIP or Office document \> enable macros \> batch file dropped to C:\\ProgramData\\directory \> web traffic for Emotet DLL \> Emotet DLL \> Emotet C2 traffic](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-2.jpeg) Figure 3. Chain of events for Emotet infections seen on Monday, Nov. 23, 2021.

Emotet targets include various areas around the world. But even if victims are non-English speakers, templates for the Office documents are still in English as shown below in Figures 4 and 5 from an email targeting Italy.
![Emotet targets include various areas around the world. But even if victims are non-English speakers, templates for the Office documents are still in English as shown here in an email targeting Italy.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-3.jpeg) Figure 4. Screenshot of Emotet email targeting Italy on Nov. 23, 2021. ![Emotet targets include various areas around the world. But even if victims are non-English speakers, templates for the Office documents are still in English as shown here in an attachment from an Italian email containing an Excel spreadsheet.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-4.jpeg) Figure 5. Attachment from Italian email contained Excel spreadsheet for Emotet with an English template.

At this time, enabling macros did not directly download and run the Emotet DLL. Instead, the macro code dropped a batch file shown in Figure 6 and ran it with the following command:

C:\\WINDOWS\\system32\\cmd.exe /c c:\\programdata\\sdfhiuwu.bat
![At this time, enabling macros did not directly download and run the Emotet DLL. Instead, the macro code dropped a batch file shown here and ran it with the following command: C:\\WINDOWS\\system32\\cmd.exe /c c:\\programdata\\sdfhiuwu.bat](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-5.jpeg) Figure 6. Batch file dropped after enabling macros for an Emotet infection on Nov. 23, 2021.

As an evasion technique, obfuscated script in the batch file generates a PowerShell command to retrieve an Emotet DLL and run it on the victim's host. The PowerShell command uses a base64-encoded string as shown below in Figure 7.
![As an evasion technique, obfuscated script in the batch file generates a PowerShell command to retrieve an Emotet DLL and run it on the victim’s host. The PowerShell command uses a base64-encoded string as shown](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-6.jpeg) Figure 7. PowerShell command using base64 encoded string.

Converting the base64 string to ASCII text reveals the script shown below in Figure 8. This script is designed to retrieve an Emotet DLL from one of seven URLs and save it to the C:\\ProgramData\\ directory. The Emotet DLL is run with rundll32.exe using a random string of characters as the entry point.
![Converting the base64 string to ASCII text reveals the script shown This script is designed to retrieve an Emotet DLL from one of seven URLs and save it to the C:\\ProgramData\\ directory. The Emotet DLL is run with rundll32.exe using a random string of characters as the entry point.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-7.jpeg) Figure 8. Deobfuscated script from the base64 string in Figure 4.

The new Emotet DLL is similar to Emotet DLLs before the January 2021 takedown. Emotet is made persistent under a randomly named folder under the infected user's AppData\\Local\\Temp directory. The modified date of the persistent DLL is backdated exactly one week prior to the infection. Emotet is made persistent through a Windows Registry update. Figure 9 shows an example from Nov. 23.
![Emotet is made persistent through a Windows Registry update, as shown.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-8.jpeg) Figure 9. Registry update to keep Emotet persistent after a reboot.

Since Emotet reappeared in November 2021, post-infection C2 activity consists of encrypted HTTPS traffic. Certificate issuer data for Emotet C2 HTTPS traffic uses generic values often seen with other malware families. Figure 10 shows an example of Emotet C2 activity filtered in Wireshark to reveal the certificate issuer data.
![An example of Emotet C2 activity filtered in Wireshark to reveal the certificate issuer data. The key section is surrounded by a red box with a red arrow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-9.jpeg) Figure 10. Reviewing certificate issuer data of Emotet HTTPS C2 traffic in Wireshark.

As shown above in Figure 10, certificate issuer data for Emotet C2 HTTPS traffic is:

id-at-countryName=**GB**id-at-statOrProvinceName=**London**id-at-localityName=**London**id-at-organizationName=**Global Security**id-at-organizationalUnitName=**IT Department**id-at-commonName=**example.com**

Of note, other malware families have used similar certificate issuer data, so this is not necessarily unique to Emotet.

On Nov.r 30, Emotet switched tactics again and [began abusing Microsoft's App Installer](https://www.malware-traffic-analysis.net/2021/11/30/index.html) as part of its infection chain.

## Emotet Abuses Microsoft App Installer

Now disabled by Microsoft, App Installer is a [protocol for Windows 10](https://docs.microsoft.com/en-us/windows/msix/app-installer/installing-windows10-apps-we) used to install software directly from a web server, and it used XML-based app installer files with the extension .appinstaller. This protocol had been [previously abused for BazarLoader malware attacks](https://www.bleepingcomputer.com/news/security/windows-10-app-installer-abused-in-bazarloader-malware-attacks/) in November 2021. Figure 11 shows the flow chart for this type of Emotet infection.
![Flow chart for Emotet infections abusing Microsoft's App Installer protocol: email \> link from email \> fake PDF report page \> link from fake PDF report page \> appinstaller (XML file) \> web traffic generated by appinstaller \> appxbundle (zip archive) \> web traffic generated by files in appxbundle \> Emotet DLL \> Emotet C2 activity](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-10.jpeg) Figure 11. Flow chart for Emotet infections abusing Microsoft's App Installer Protocol.

The attack technique starts with complaint report-themed emails with links to malicious pages. These malicious pages are hosted on compromised websites, and they spoof Google Drive by using the same style of Google Drive pages, including a Google Drive icon that appears in the browser tab. The pages have links to supposedly preview a PDF-based complaint report. The link actually leads to a malicious .appinstaller file designed to infect a vulnerable Windows 10 host with Emotet.

Below, Figure 12 shows a thread-hijacked email from Nov. 30 with the malicious link, and Figure 13 shows the associated complaint page with a link to the malicious .appinstaller file.
![Thread-hijacked email from Nov. 30. The malicious link appears toward the top and seems to be a PDF. The actual destination of the malicious link is superimposed in red over the screenshot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-11.jpeg) Figure 12. Thread-hijacked email from Nov. 30 with link to page for malicious app installer. ![Fake complaint report page links to .appinstaller file for Emotet. Red arrows show what happens if the user clicks the "Preview PDF" button shown in the screenshot. The malicious link that is the actual destination of the button is superimposed over the screenshot in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-12.jpeg) Figure 13. Fake complaint report page with link to .appinstaller file for Emotet.

As shown above in Figure 13, the .appinstaller file pretends to be an Adobe PDF component. In this case, criminals were abusing Microsoft Azure to host the malicious files. Below, Figure 14 shows a malicious .appinstaller file opened in a text editor.
![A malicious .appinstaller file opened in a text editor. The file retrieves a malicious ZIP archive appended with an .appxbundle file extension from the same server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-13.jpeg) Figure 14. Malicious .appinstaller file used for Emotet on Nov. 30.

The malicious .appinstaller file shown above in Figure 14 retrieves a malicious ZIP archive appended with an .appxbundle file extension from the same server. Below, Figure 15 shows contents of the malicious .appxbundle.
![Contents of the malicious .appxbundle. It contains various files including ZIP archives with an .appx file extension. The entire .appxbundle is designed to retrieve an Emotet DLL and run it on a vulnerable Windows host.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-14.jpeg) Figure 15. Malicious .appxbundle used for Emotet infection on Nov. 30.

The malicious .appxbundle impersonating an Adobe program contains various files including ZIP archives with an .appx file extension. Together, the entire .appxbundle is designed to retrieve an Emotet DLL and run it on a vulnerable Windows host.

Indicators and further details from the Nov. 30 activity can be found at [Malware Traffic Analysis](https://www.malware-traffic-analysis.net/2021/11/30/index.html). Due to the nature of these app installer files, this infection method was initially difficult to detect. Fortunately, Microsoft quickly shut down Azure file servers hosting the app installer files. [Microsoft has also disabled the app installer protocol](https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-msix-protocol-handler-abused-in-emotet-attacks/), so this no longer remains an avenue of attack for Emotet or other malware.

[Appendix B](#Appendix-B-Emotet-epoch-4-abusing-App-Installer) lists indicators of compromise from an Emotet infection abusing Microsoft's App Installer on Nov. 30.

## Emotet in December 2021

Throughout November 2021, examples of Emotet infections revealed data exfiltration and spambot activity. No indicators of followup malware were publicly reported until December 2021. By Dec. 7, the Cryptolaemus research team [confirmed Cobalt Strike had been deployed](https://twitter.com/Cryptolaemus1/status/1468266929014157316) to Emotet-infected Windows hosts.

December 2021 saw at least one more wave of emails from Emotet attempting to abuse Microsoft's App Installer protocol. However, Emotet quickly moved on to other infection patterns and used different templates for Office documents, mostly Excel spreadsheets.

In the week leading to Christmas day, Emotet emails contained links to web pages on various compromised websites. These pages also pretended to be from Google Drive, and they had links to download malicious Excel files. In this case, Emotet started using a new infection pattern as shown in Figure 16.
![Emotet infection pattern seen from Dec. 21-Dec. 24: email \> link from email \> fake complaint report page \> link from complaint report page \> Excel file \> enable macros \> cmd.exe runs mshta.exe on HTML application (.hta) file hosted at a web URL \> web traffic for .hta file \> powershell.exe runs script hosted on another web URL \> web traffic for PowerShell script \> web traffic for Emotet DLL \> Emotet DLL \> Emotet C2 traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-15.jpeg) Figure 16. Emotet infection pattern seen from Dec. 21-Dec. 24.

Above, Figure 16 reveals a process Emotet occasionally used through at least February 2022. We [previously reported details on one such variation](https://unit42.paloaltonetworks.com/new-emotet-infection-method/) from January. [Appendix C](#Appendix-C-Emotet-epoch-4-infection) lists indicators of compromise from an Emotet infection using this method on Dec. 21.

Below, Figure 17 shows an email from Dec. 23 pushing Emotet, Figure 18 displays the website from the email link, and Figure 19 reveals the downloaded Excel spreadsheet.
![Email from Dec. 23 pushing Emotet. A red arrow draws attention to the malicious link, and the malicious link's actual destination is shown in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-16.jpeg) Figure 17. Example of email from Dec. 23 pushing Emotet. ![Web page delivering malicious Excel spreadsheet. the screenshot shows the option to open or save the malicious spreadsheet.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-17.jpeg) Figure 18. Web page delivering malicious Excel spreadsheet leading to Emotet on Dec. 23. ![The malicious Excel spreadsheet, 8278500.xls. The screenshot shows that the spreadsheet opens with a request to enable macros.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-18.jpeg) Figure 19. Malicious Excel spreadsheet downloaded from page shown in Figure 17.

On Thursday, Dec. 24, we saw similar emails with Christmas-themed subject lines and holiday wishes in the message text. This wave of emails delivered the same style of Excel spreadsheet shown above in Figure 19.

Below, Figure 20 shows one of these Christmas-themed emails, and Figure 21 displays the associated web page that delivered an Excel spreadsheet.
![Christmas-themed email from Dec. 24 pushing Emotet. A red arrow indicates the malicious link, and its actual destination is shown in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-19.jpeg) Figure 20. Example of Christmas-themed email from Dec. 24 pushing Emotet. ![Website delivering a malicious Excel spreadsheet leading to Emotet. The page says, "File 'Christmas Greetings' is ready for open."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-20.jpeg) Figure 21. Web page delivering malicious Excel spreadsheet leading to Emotet on Dec. 24.

After Dec. 24, Emotet stopped spamming until after the new year.

## Emotet in January 2022

On Tuesday, Jan. 11, 2022, Emotet resumed [spamming after its holiday break](https://twitter.com/Cryptolaemus1/status/1480893070870818820). The emails continued with links to fake complaint pages, and the pages were sometimes customized to include the recipient's name. This method was prevalent until Jan. 20.

Figures 22-24 show one such example from Jan. 20. In this example, the recipient's name has been sanitized to read as "Solomon Grundy" with an AOL email address, and the spoofed sender has been sanitized to read as alan.scott@thegreenlantern\[.\]net.
![Emotet email from Jan. 20. The malicious link is indicated by a red arrow. Its actual destination is shown in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-21.jpeg) Figure 22. Emotet email from Jan. 20. ![Fake complaint report page attempts to deliver a malicious Excel spreadsheet as shown. The screenshot reads, "File 'Preview Complaint Report in XLS' is ready for open."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-22.jpeg) Figure 23. Fake complaint report page with recipient's name sending Excel spreadsheet for Emotet. ![Excel spreadsheet for Emotet downloaded from fake complaint report web page. Note that the spreadsheet attempts to trick the user into enabling macros.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-23.jpeg) Figure 24. Excel spreadsheet for Emotet downloaded from fake complaint report web page.

[Appendix D](#Appendix-D-Emotet-epoch-5-infection) lists indicators of compromise from an Emotet infection using this method on Jan. 11.

By Friday, Jan. 21, Emotet emails went back to using attached Excel spreadsheets or password-protected ZIP archives containing Excel spreadsheets. Throughout the rest of the month, Excel spreadsheets for Emotet alternated between the template shown above in Figure 24 and the template shown below in Figure 25.
![Excel spreadsheet template for Emotet seen during the last full week of January 2022. The spreadsheet opens a window that says, "This document is protected. Previewing is not available for protected documents. You have to press "ENABLE EDITING" and "ENABLE CONTENT" buttons to preview this document.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/05/word-image-24.jpeg) Figure 25. Excel spreadsheet template seen during the last full week of January 2022.

In January, we continued to see reports of Emotet pushing Cobalt Strike. During our lab tests, we routinely saw Emotet-infected hosts generate spambot activity starting from 35-45 minutes after the initial infection.

## Conclusion

Since its return in November 2021, Emotet has once again become one of the most prolific malware families in our current threat landscape. Hundreds of thousands of emails can be generated each day Emotet is actively spamming. Hashbusting, code obfuscation and other evasion techniques make Emotet a significant threat.

Windows users can lower their risk from Emotet through spam filtering, proper system administration and ensuring their software is patched and up to date. Palo Alto Networks customers are further protected from Emotet through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) and [Threat Prevention](https://www.paloaltonetworks.com/network-security/threat-prevention) subscriptions.

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

Due to hashbusting, daily changes in malware URLs and frequent changes for infection patterns, we can see hundreds of new indicators for Emotet every day. These indicators are too numerous and changes are too frequent to be useful in any single list. However, [abuse.ch](https://abuse.ch/) is a research project that provides free trackers for [Emotet botnet command and control servers](https://feodotracker.abuse.ch/browse/emotet/), [URLs hosting Emotet malware](https://threatfox.abuse.ch/browse/tag/Emotet/) and [Emotet malware samples](https://bazaar.abuse.ch/browse/tag/Emotet/).

Appendices [A](#Appendix-A-Emotet-epoch-4-activity), [B](#Appendix-B-Emotet-epoch-4-abusing-App-Installer), [C](#Appendix-C-Emotet-epoch-4-infection) and [D](#Appendix-D-Emotet-epoch-5-infection) provide a small selection of indicators referenced in this blog post.

## Appendix A: Emotet epoch 4 activity on Nov. 18, 2021

##### **SHA256 hashes for seven examples of password-protected ZIP archives:**

a1ab66a0fbb84a29e5c7733c42337bc733d8b3c11e2d9f9e4357f47fb337c4d5 3.zip  
176cfa7f0742d5a79b9cfbf266c437b965fc763cf775415ca251c6bb2dd5e9e5 9.zip  
6c34e373479e1a7485025dc3ffa5d23db999aea83e4f3759bd8381fb88e2bbbf 435.zip  
8dc28ac1c66f3d17794bb0059445f4deb9db029eb6d4ea1adca734d035bdaecf 1811.zip  
4668e7d6bdb00fb80807ed91eef5ac9f6ba0dfd50d260d3e0240847b0ec16f69 18112021.zip  
bfdad57171267921a678ba9d86fd096c00197524698cc03a84d2cfeefdca5587 433492807279.zip  
66c34636aaf73f74df8da9981ca6054eb4143d1761dbde8e0e83899805590db2 763325738862.zip

##### **Passwords for the above ZIP archives:**

3\.zip password: 008  
9\.zip password: 3854  
435\.zip password: 636  
1811\.zip password: 9483  
18112021\.zip password: 2927  
433492807279.zip password: 209  
763325738862.zip password: 339

##### **SHA256 hashes for seven extracted Word documents:**

304fba4a048904744d6d1c4d8bfd5d7b4019c2c45aba0499d797ee0d6807dfa8 3.doc  
e5f3a7e75c03d45462992b0a973e7e25b533e293724590c9eb34f5ee729039b0 9.doc  
0cacc247469125b5e0977b9de9814db0eb642c109ca5d13ee9c336aef2ec4c19 435.doc  
801ec1ec71051838efe75fd89344b676fa741d9e7718e534f119c57a899f4792 1811.doc  
cbddc8fea92cdf40f8efac2fe8fa534d52d90cccecbb914f3827002f680da98a 18112021.doc  
fccaf2af38484493d763b0ea37e68a40eb6def3030cfa975fa8d389e96b49378 433492807279.doc  
d655ab6b9350ec4f64c735cd23be62ca87d49165b244cefe75ad0dbb061de3d4 763325738862.doc

##### **URLs generated by the above Word documents:**

hxxp://jamaateislami\[.\]com/wp-admin/FKyNiHeRz1/  
hxxp://voltaicplasma\[.\]com/wp-includes/wkCYpDihyc8biTPn444B/  
hxxp://linebot.gugame\[.\]net/images/RX6MVSCgGr/  
hxxp://lpj917\[.\]com/wp-content/Cc4KG1MDR4xAWp91SjA/  
hxxp://html.gugame\[.\]net/img/5xUBiRIQ4s3EtKEv67Ebn/  
hxxp://xanthelasmaremoval\[.\]com/wp-includes/VVVcpYsRtGgjQqfgjxbS/  
hxxp://giadinhviet\[.\]com/pdf/log\_in/8kQBFUyohsDRGCJx/

##### **Example of Emotet DLL file:**

**SHA256 hash:**  
555dff455242a5f82f79eecb66539bfd1daa842481168f1f1df911ac05a1cfba  
**File size:** 485,376 bytes  
**File location:** hxxp://jamaateislami\[.\]com/wp-admin/FKyNiHeRz1/  
**File location:** C:\\ProgramData\\1245045870.dll  
**File location:** C:\\Users\\\[username\]\\AppData\\Local\\Tzbklmcf\\ljkklzcncxkf.pgk  
**Run method from Windows Registry update:** rundll32.exe *\[filename\]* ,truHNmRuL  
**Note 1:** This was generated using 1811.doc  
**Note 2:** The entry point used with rundll32.exe can be any alpha-numeric value

##### HTTPS Emotet C2 traffic from an infected Windows host:

51\.178.61\[.\]60 port 443  
103\.161.172\[.\]108 port 443  
122\.129.203\[.\]163 port 443

## Appendix B: Emotet epoch 4 abusing App Installer on Nov. 30, 2021

##### Link from email:

hxxp://hispanicaidgroup\[.\]org/ufay0vq/keWIgzwT/

##### Malicious App Installer:

**SHA256 hash:**  
450cba4a0f2b8c14dee55c33c9c0f522a4dddd1b463e39e8e736ed37dc2fac74  
**File size:** 472 bytes  
**File location:** hxxps://locstorageinfo.z13.web.core.windows\[.\]net/ioocceneen.appinstaller

##### **Malicious Appxbundle:**

**SHA256 hash:**  
7c55c3656184b145b3b3f6449c05d93fa389650ad235512d2f99ee412085cf3a  
**File size:** 1,261,364 bytes  
**File location:** hxxps://locstorageinfo.z13.web.core.windows\[.\]net/ioocceneen.appxbundle

##### Malicious executable contained in Appxbundle:

**SHA256 hash:**  
36a81cd64e7649d9f91925194e89e8463c980682596eef19c4f5df6e1ac77b2a  
**File size:** 192,800 bytes  
**In Appixbundle at:**  
ioocceneen.appxbundle/Adobe\_1.2.0.0\_x86/CustomParts/wsprotocol.exe

##### Example of Emotet DLL:

**SHA256 hash:**  
a04714dcfad52b9dbf2f649810a6c489c5eb2a15118043f0173571310597b8cb  
**File size:** 643,147 bytes  
**File location:** hxxp://www.thebanditproject\[.\]com/wp-content/BvZK54PFsCqKio6/  
**File location:** C:\\Users\\*\[username\]* \\AppData\\Local\\Pvglfpllzel\\bhryuac.wmn  
**Run method:** rundll32.exe *\[filename\]* ,*\[any alpha-numeric value\]*

##### HTTPS Emotet C2 traffic from an infected Windows host:

46\.55.222\[.\]11 port 443  
163\.172.50\[.\]82 port 443

## Appendix C: Emotet epoch 4 infection on Dec. 21, 2021

##### Attached Excel file from email:

**SHA256 hash:**  
fcf5500a8b46bf8c7234fb0cc4568e2bd65b12ef8b700dc11ff8ee507ba129da  
**File size:** 194,273 bytes  
**File name:** REP\_1671971987654103376.xls

##### HTA file:

**SHA256 hash:**  
97ebdff655fa111863fbd084f99187c9b6b369fe88fdb1333f8b89aac09fc48d  
**File size:** 10,980 bytes  
**File location:** hxxp://87.251.86\[.\]178/pp/\_.html

##### Powershell script:

**SHA256 hash:**  
a08271fe6d67cc6cf678683f58e22412e6872a985a03b8444584bea57aa3cbb7  
**File size:** 721 bytes  
**File location:** hxxp://87.251.86\[.\]178/pp/PP.PNG

##### URLs generated by the above Powershell script:

hxxp://mustache.webstory\[.\]sa/wp-includes/cRwe2Pkxasj/  
hxxps://vdevigueta\[.\]com/wp-admin/qYOwD7kPD6JX/  
hxxp://bujogradba\[.\]com/5tvjjl/qiP8H0W5GmR5P9fGIw/  
hxxps://daxinghuo\[.\]com/get/oU8lM4P/  
hxxp://masl\[.\]cn/1/4Ilcpoj6PjTsj3eAR/

##### Example of Emotet DLL:

**SHA256 hash:**  
7c35902055f69af2cbb6c941821ceba3d79b2768dd2235c282b195eb48cc6c83  
**File size:** 1,257,472 bytes  
**File location:** hxxp://mustache.webstory\[.\]sa/wp-includes/cRwe2Pkxasj/  
**File location:** C:\\Users\\Public\\Documents\\ssd.dll  
**File location:** C:\\Users\\*\[username\]* \\AppData\\Local\\Piqvlxzjzu\\vrjlv.srn  
**Run method:** rundll32.exe *\[filename\]* ,*\[any alpha-numeric value\]*

##### HTTPS Emotet C2 traffic from an infected Windows host:

54\.37.212\[.\]235 port 80  
144\.202.34\[.\]169 port 443

## Appendix D: Emotet epoch 5 infection on Jan. 11, 2022

##### Example of link in email for fake complaint page:

hxxp://goodmarketinggroup\[.\]com/newish/562\_9559085/

##### URL to download Excel spreadsheet:

hxxp://goodmarketinggroup\[.\]com/newish/562\_9559085/?i=1

##### Example of downloaded Emotet Excel file:

**SHA256 hash:**  
292826fa66737d718d0d23f5842dc88e05c8ba5ade7e51212dded85137631b31  
**File size:** 85,352 bytes  
**File name:** 06028\_2603.xlsm

##### Three URLs to download an Emotet DLL after enabling macros:

hxxp://mammy-chiro\[.\]com/case/ZTkBzbz/  
hxxp://bluetoothheadsetreview\[.\]xyz/wp-includes/xmdHAGgfki/  
hxxp://topline36\[.\]xyz/wp-includes/css/BB9Ajvjs89U9O/

##### Example of Emotet DLL:

**SHA256 hash:**  
4978285fc20fb2ac2990a735071277302c9175d16820ac64f326679f162354ff  
**File size:** 481,792 bytes  
**File location:** hxxp://mammy-chiro\[.\]com/case/ZTkBzbz/  
**File location:** C:\\Users\\*\[username\]* \\dwa.ocx  
**File location:** C:\\Users\\*\[username\]* \\AppData\\Local\\Fhcnkauwkz\\gavlgclbak.wwa  
**Run method:** rundll32.exe *\[filename\]* ,*\[any alpha-numeric value\]*

##### HTTPS Emotet C2 traffic from an infected Windows host:

41\.226.30\[.\]6 port 8080  
45\.138.98\[.\]34 port 80  
62\.141.45\[.\]103 port 443  
161\.97.77\[.\]73 port 443

## Additional Resources

* [Emotet Malware](https://www.cisa.gov/uscert/ncas/alerts/aa20-280a) - United States Department of Homeland Security, Cybersecurity \& Infrastructure Security Agency (CISA)
* [Case Study: Emotet Thread Hijacking, an Email Attack Technique](https://unit42.paloaltonetworks.com/emotet-thread-hijacking/) - Unit 42, Palo Alto Networks
* [World's most dangerous malware EMOTET disrupted through global action](https://www.europol.europa.eu/media-press/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action) - Europol
* [Emotet Returns](https://isc.sans.edu/forums/diary/Emotet+Returns/28044/) - Internet Storm Center
* [Emotet hashbusting](https://twitter.com/malwaretechblog/status/1251606958592757760) - Tweet by @MalwareTechBlog
* [Emotet uses appinstaller for infection](https://www.malware-traffic-analysis.net/2021/11/30/index.html) - malware-traffic-analysis.net
* [Emotet now spreads via fake Adobe Windows App Installer packages](https://www.bleepingcomputer.com/news/security/emotet-now-spreads-via-fake-adobe-windows-app-installer-packages/) - BleepingComputer
* [Emotet dropping Cobalt Strike](https://twitter.com/Cryptolaemus1/status/1468266929014157316) - Tweet by @Cryptolaemus1
* [New Emotet Infection Method](https://unit42.paloaltonetworks.com/new-emotet-infection-method/) - Unit 42, Palo Alto Networks

Back to top

### Tags

* [Emotet](https://unit42.paloaltonetworks.com/tag/emotet/ "Emotet")
* [Macros](https://unit42.paloaltonetworks.com/tag/macros/ "Macros")
* [MealyBug](https://unit42.paloaltonetworks.com/tag/mealybug/ "MealyBug")
* [Mummy Spider](https://unit42.paloaltonetworks.com/tag/mummy-spider/ "Mummy Spider")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [TA542](https://unit42.paloaltonetworks.com/tag/ta542/ "TA542")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: A Look Into Public Clouds From the Ransomware Actor's Perspective](https://unit42.paloaltonetworks.com/ransomware-in-public-clouds/ "A Look Into Public Clouds From the Ransomware Actor's Perspective")

### Table of Contents

* 

### Related Articles

* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
