S0367: Emotet
Security context for executives and security teams
S0367: Emotet describes [Emotet](https://attack.mitre.org/software/S0367) is a modular malware variant which is primarily used as a downloader for other malware variants such as [TrickBot](https://attack.mitre.org/software/S0266) and [IcedID](https://attack.mitre.org/software/S0483). Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.(Citation: Trend Micro Banking Malware Jan 2019)
Executive priority
S0367: Emotet is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S0367: Emotet by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S0367: Emotet appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Emotet
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1033 | System Owner/User Discovery | Emotet has enumerated all users connected to network shares. |
| Enterprise | T1570 | Lateral Tool Transfer | Emotet has copied itself to remote systems using the `service.exe` filename.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | |
| Enterprise | T1552.001 | Credentials In FilesSub-technique | |
| Enterprise | T1110.001 | Password GuessingSub-technique | |
| Enterprise | T1047 | Windows Management Instrumentation | Emotet has used WMI to execute powershell.exe.CitationCarbon Black Emotet Apr 2019 |
| Enterprise | T1571 | Non-Standard Port | |
| Enterprise | T1027.001 | Binary PaddingSub-technique | Emotet inflates malicious files and malware as an evasion technique.Citationemotet_trendmicro_mar2023 |
| Enterprise | T1218.010 | Regsvr32Sub-technique | Emotet uses RegSvr32 to execute the DLL payload.Citationemotet_trendmicro_mar2023 |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1204.002 | Malicious FileSub-technique | |
| Enterprise | T1134.001 | Token Impersonation/TheftSub-technique | |
| Enterprise | T1078.003 | Local AccountsSub-technique | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | |
| Enterprise | T1132.001 | Standard EncodingSub-technique | |
| Enterprise | T1135 | Network Share Discovery | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Emotet has used HTTP for command and control.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1041 | Exfiltration Over C2 Channel | |
| Enterprise | T1027.009 | Embedded PayloadsSub-technique | |
| Enterprise | T1105 | Ingress Tool Transfer | Emotet can download follow-on payloads and items via malicious `url` parameters in obfuscated PowerShell code.CitationPincus Emotet 2020 |
| Enterprise | T1114 | Email Collection | |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1555.003 | Credentials from Web BrowsersSub-technique | |
| Enterprise | T1059.001 | PowerShellSub-technique | |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1059.005 | Visual BasicSub-technique | |
| Enterprise | T1204.001 | Malicious LinkSub-technique | |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | |
| Enterprise | T1003.001 | LSASS MemorySub-technique | |
| Enterprise | T1040 | Network Sniffing | |
| Enterprise | T1620 | Reflective Code Loading | Emotet has reflectively loaded payloads into memory.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Emotet uses obfuscated URLs to download a ZIP file.Citationemotet_trendmicro_mar2023 |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1027.002 | Software PackingSub-technique | |
| Enterprise | T1055.012 | Process HollowingSub-technique | Emotet uses a copy of `certutil.exe` stored in a temporary directory for process hollowing, starting the program in a suspended state before loading malicious code.Citationemotet_trendmicro_mar2023 |
| Enterprise | T1057 | Process Discovery | Emotet has been observed enumerating local processes.CitationASEC Emotet 2017 |
| Enterprise | T1055.001 | Dynamic-link Library InjectionSub-technique | |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | |
| Enterprise | T1543.003 | Windows ServiceSub-technique | |
| Enterprise | T1573 | Encrypted Channel | Emotet has encrypted data before sending to the C2 server.CitationFortinet Emotet May 2017 |
| Enterprise | T1106 | Native API | Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1016.002 | Wi-Fi DiscoverySub-technique | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.CitationBinary Defense Emotes Wi-Fi Spreader |
| Enterprise | T1087.003 | Email AccountSub-technique | |
| Enterprise | T1210 | Exploitation of Remote Services |
Groups, software, and campaigns
G0102: Wizard Spider
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.7 | Current bundle | 7a8b5571d5e9… | ||
| 19.1 | 1.7 | Older bundle | 7a8b5571d5e9… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Trend Micro Banking Malware Jan 2019
Salvio, J.. (2014, June 27). New Banking Malware Uses Network Sniffing for Data Theft. Retrieved March 25, 2019.
Open source URL - [2]Trend Micro Emotet Jan 2019
Trend Micro. (2019, January 16). Exploring Emotet's Activities . Retrieved March 25, 2019.
Open source URL - [3]US-CERT Emotet Jul 2018
US-CERT. (2018, July 20). Alert (TA18-201A) Emotet Malware. Retrieved March 25, 2019.
Open source URL - [4]CIS Emotet Dec 2018
CIS. (2018, December 12). MS-ISAC Security Primer- Emotet. Retrieved March 25, 2019.
Open source URL - [5]Malwarebytes Emotet Dec 2017
Smith, A.. (2017, December 22). Protect your network from Emotet Trojan with Malwarebytes Endpoint Security. Retrieved January 17, 2019.
Open source URL - [6]Symantec Emotet Jul 2018
Symantec. (2018, July 18). The Evolution of Emotet: From Banking Trojan to Threat Distributor. Retrieved March 25, 2019.
Open source URL - [7]Secureworks Emotet Nov 2018
Mclellan, M.. (2018, November 19). Lazy Passwords Become Rocket Fuel for Emotet SMB Spreader. Retrieved March 25, 2019.
Open source URL - [8]Talos Emotet Jan 2019
Brumaghin, E.. (2019, January 15). Emotet re-emerges after the holidays. Retrieved March 25, 2019.
Open source URL - [9]Picus Emotet Dec 2018
Özarslan, S. (2018, December 21). The Christmas Card you never wanted - A new wave of Emotet is back to wreak havoc. Retrieved March 25, 2019.
Open source URL - [10]Kaspersky Emotet Jan 2019
Shulmin, A. . (2015, April 9). The Banking Trojan Emotet: Detailed Analysis. Retrieved March 25, 2019.
Open source URL - [11]CIS Emotet Apr 2017
CIS. (2017, April 28). Emotet Changes TTPs and Arrives in United States. Retrieved January 17, 2019.
Open source URL - [12]Red Canary Emotet Feb 2019
Donohue, B.. (2019, February 13). https://redcanary.com/blog/stopping-emotet-before-it-moves-laterally/. Retrieved March 25, 2019.
Open source URL - [13]ESET Emotet Nov 2018
ESET . (2018, November 9). Emotet launches major new spam campaign. Retrieved March 25, 2019.
Open source URL - [14]Emotet
(Citation: Trend Micro Banking Malware Jan 2019)(Citation: Kaspersky Emotet Jan 2019)(Citation: CIS Emotet Apr 2017)(Citation: Malwarebytes Emotet Dec 2017)(Citation: Symantec Emotet Jul 2018)(Citation: US-CERT Emotet Jul 2018)(Citation: ESET Emotet Nov 2018)(Citation: Secureworks Emotet Nov 2018)(Citation: Talos Emotet Jan 2019)(Citation: Trend Micro Emotet Jan 2019)(Citation: CIS Emotet Dec 2018)(Citation: Picus Emotet Dec 2018)(Citation: Red Canary Emotet Feb 2019)
- [15]Geodo
(Citation: Trend Micro Emotet Jan 2019)
- [16]mitre-attackS0367Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
