Emotet, a prolific banking-trojan-turned-initial-access-broker, returned to the threat landscape on November 14, 2021 following a law enforcement disruption and arrests in January 2021. The revived variant is being distributed via the TrickBot botnet and direct spam campaigns using reply-chain phishing emails with malicious macro-enabled Office documents and password-protected archives, and now communicates with C2 infrastructure over HTTPS with updated encryption compared to prior versions.
trickbot
2 posts
Return of Emotet malware | Zscaler Inside a TrickBot Variant Using DNS Tunneling for C2 FortiGuard Labs identified a TrickBot variant that uses DNS tunneling for C2 communication instead of HTTP, embedding XOR-encrypted data in DNS queries and encoding response payloads within IPv4 address octets. The malware establishes persistence via Windows Task Scheduler disguised as software updates, stores configuration in NTFS Alternate Data Streams, and employs runtime string decryption and hash-based API resolution to evade analysis. Its modular architecture supports process injection (hollowing, doppelgänging), DLL execution via rundll32, PowerShell execution, and raw shellcode execution, retaining the full capability set of the TrickBot family.