Emotet

Category: loader · Aliases: geodo, heodo, mealybug · Sample count (EMBER 2018): 12,943 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Emotet is a sophisticated modular banking trojan that first appeared in 2014 and evolved into one of the most prolific malware-as-a-service platforms in cybercrime, distributing other payloads including Trickbot, Qakbot, and Ryuk ransomware. It spreads primarily through phishing emails carrying malicious Office documents with macros, and once installed it harvests credentials, propagates across local networks, and downloads secondary payloads. CISA has called Emotet one of the most costly and destructive malware affecting state, local, tribal, and territorial governments. International law enforcement disrupted its infrastructure in January 2021, though operations have since resumed. Defense requires email filtering, macro disablement, and network segmentation.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1566.001 T1059.001 T1071.001 T1547.001 T1055

Authoritative Advisory

CISA has published an advisory on this family: https://www.cisa.gov/news-events/alerts/2020/10/06/emotet-malware

Frequently Asked Questions

What is Emotet?

Emotet is a sophisticated modular banking trojan that first appeared in 2014 and evolved into one of the most prolific malware-as-a-service platforms in cybercrime, distributing other payloads including Trickbot, Qakbot, and Ryuk ransomware. It spreads primarily through phishing emails carrying malicious Office documents with macros, and once installed it harvests credentials, propagates across local networks, and downloads secondary payloads. CISA has called Emotet one of the most costly and destructive malware affecting state, local, tribal, and territorial governments. International law enforcement disrupted its infrastructure in January 2021, though operations have since resumed. Defense requires email filtering, macro disablement, and network segmentation.

How does Emotet spread?

Emotet spreads primarily through phishing emails with malicious Word, Excel, or OneNote attachments, hijacked email threads, and password-protected ZIP archives.

What are the signs of an Emotet infection?

Outbound SMTP from unexpected processes, scheduled tasks with random alphanumeric names, secondary infections (Trickbot, Qakbot, Ryuk) appearing within hours, and antivirus detections for Emotet, Geodo, or Heodo indicate compromise.

What should I do if I think I have Emotet on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/emotet.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.