Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Emotet malware returns; here's what to look out for

By Maria Henriquez
malware-virus-hack-freepik4872.jpg
November 19, 2021

Once described as “the world’s most dangerous malware,” Emotet has allegedly returned and is being installed on Windows systems infected with TrickBot malware. 


First, some background. Emotet was one of the most professional and long-lasting cybercrime services. Discovered as a Trojan in 2014, the malware evolved into the go-to solution for cybercriminals over the years. According to Europol, the Emotet infrastructure acted as a primary door opener for computer systems on a global scale. Once access was established, these were sold to other top-level criminal groups to deploy further illicit activities such as data theft and extortion through ransomware.


What made it so dangerous, Europol says, was that the malware was offered for hire to other cybercriminals to install different types of malware, such as banking Trojans or ransomware, onto a victim’s computer.  This type of attack is called a ‘loader’ operation, and Emotet is said to be one of the most prominent players in the cybercrime world as other malware operators like TrickBot and Ryuk have benefited from it.  Its unique way of infecting networks by spreading the threat laterally after gaining access to just a few devices in the network made it one of the most resilient malware in the wild. 


Europol severely disrupted Emotet earlier this year by gaining control of its infrastructure and taking it down from the inside. Infected machines of victims were redirected towards law enforcement-controlled infrastructure to effectively disrupt the threat actors’ activities. 


Now, researchers have recently observed the TrickBot trojan launching what appears to be a new loader for the notorious malware onto Windows machines. 


“We observed on several of our Trickbot trackers that the bot tried to download a DLL to the system. According to internal processing, these DLLs have been identified as Emotet. However, since the botnet was taken down earlier this year, we were suspicious about the findings and conducted an initial manual verification,” Luca Ebach, a security researcher at G Data, wrote in a blog post. 


Other cybersecurity researchers from Crypolaemus and AdvInterl also confirmed that Emotet seems to have returned.


According to security researcher Brad Duncan, the Emotet botnet had begun spamming multiple email campaigns, using replay-chain emails, to trick recipients into opening the malicious files and infecting the devices with the malware. 


Stefano De Blasi, Cyber Threat Intelligence Analyst at Digital Shadows, a San Francisco-based provider of digital risk protection solutions, explains, “According to security researchers examining the malware’s return, Emotet is likely rebuilding part of its infrastructure with the help of TrickBot existing one. As part of these resource development efforts, the Emotet operators are likely stealing email chains to use them in further malicious activities. As we detailed in our latest blog on Fight the Pish!, cybercriminals are increasingly using email hijacking techniques during their social engineering campaigns. Once in control of a victim’s email account, threat actors can monitor conversations and identify the ideal opportunity to insert a malicious email into an existing thread. As Kim said, “While this is arguably more labor-intensive for a threat actor, it yields higher rewards too.”


De Blasi adds, “The new variant of the infamous malware reportedly follows a similar path of delivering both malicious Office or ZIP files, in addition to other command-and-control (C2) payloads. These are reportedly being distributed via the Trickbot botnet, once again highlighting the close connection between the two malware families. With this return, Emotet will likely be adopted back into the playbook of several prominent cybercriminals, which will almost certainly include ransomware groups. The removal of Emotet left a vacuum filled by some alternate malware, including Dridex, Qakbot, and IcedID. Many cybercriminal groups may return to Emotet as a tried and tested approach, although these changes will likely be reflected over several months. It will certainly take some time to rebuild Emotet’s infrastructure; however, its massive reputation in the cybercriminal community makes it a predictable choice for many threat actors looking to expand their operations.”


So, what should security teams be looking out for, you may ask. De Blasi says, “The threat posed by Emotet is significant; however, its return shouldn’t signal a dramatic shift for blue teams. Security teams should follow basic cyber security hygiene practices to ensure an adequate level of protection much in the same way as other malware variants. Email gateways to stop malicious emails from arriving, user awareness of phishing campaigns, and applying restrictions on the use of macros within Office files will assist in lowering the risk posed by most forms of malware. Additionally, monitoring for impersonating domains, enabling multi-factor authentication, and ensuring a smooth phishing reporting process are crucial steps in defending against Emotet.”

KEYWORDS: cyber security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Maria Henriquez is a former Associate Editor of Security. She covered topics including cybersecurity and physical security, risk management and more.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • covid-workplace-freepik

    Planning your organization’s return to work? Here’s what you should keep in mind.

    See More
  • Cybersecurity Leadership Images

    Threats to Look Out for in 2019 – How to Protect Mid-Tier Enterprises from Tomorrow’s Known and Unknown Cyberattacks

    See More
  • What to Look for in Travel Security and Executive Protection Services - Security Magazine

    What to Look for in Travel Security and Executive Protection Services

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Photonic Sensing: Principles and Applications for Safety and Security Monitoring

  • 150 things.jpg

    The Handbook for School Safety and Security

See More Products

Events

View AllSubmit An Event
  • January 6, 2011

    From Here to There - Advancing in the Security Field

    Learn the three components that are critical for your advancement.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing