Emotet

S0367

Malware.View on attack.mitre.org

About this malware

Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.

Techniques used47

Procedure examples47

TechniqueProcedure example
T1003.001
LSASS Memory

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1016.002
Wi-Fi Discovery

Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.

T1021.002
SMB/Windows Admin Shares

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1027.001
Binary Padding

Emotet inflates malicious files and malware as an evasion technique.

T1027.002
Software Packing

Emotet has used custom packers to protect its payloads.

T1027.009
Embedded Payloads

Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files.

T1027.010
Command Obfuscation

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1027.013
Encrypted/Encoded File

Emotet uses obfuscated URLs to download a ZIP file.

T1033
System Owner/User Discovery

Emotet has enumerated all users connected to network shares.

T1036.004
Masquerade Task or Service

Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`.

T1040
Network Sniffing

Emotet has been observed to hook network APIs to monitor network traffic.

T1041
Exfiltration Over C2 Channel

Emotet has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation

Emotet has used WMI to execute powershell.exe.

T1053.005
Scheduled Task

Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry.

T1055.001
Dynamic-link Library Injection

Emotet has been observed injecting in to Explorer.exe and other processes.

View all 47 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Banking Malware Jan 2019 Open source
    Salvio, J.. (2014, June 27). New Banking Malware Uses Network Sniffing for Data Theft. Retrieved March 25, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.