Emotet Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
October 23, 2025
Last Seen
July 23, 2026

Emotet is a malware family tracked across 11 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 23, 2026.

Related Threat Clusters

  • Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

    Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…

    4 articles · Updated June 23, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers

    A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…

    7 articles · Updated July 1, 2026
  • VoidStealer and Infostealers Bypass Chrome's App-Bound Encryption

    Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…

    11 articles · Updated May 7, 2026
  • Surge in Account Takeover Fraud Threatens Organizations

    Account takeover (ATO) fraud has surged dramatically, with a reported 354% increase in cases and $13 billion in losses in 2023. This type of cybercrime involves unauthorized access to legitimate user accounts through…

    2 articles · Updated April 29, 2026
  • Deutsche Bank Investigates Ransomware Breach by Unsafe Group

    Deutsche Bank is probing a cybersecurity incident involving an external service provider after the ransomware group Unsafe claimed to have breached the bank and leaked employee data. The group published screenshots on a…

    2 articles · Updated July 9, 2026
  • Russia's Cybercrime Landscape Shifts Amid Law Enforcement Actions

    Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…

    2 articles · Updated January 9, 2026
  • Aeternum Botnet Utilizes Polygon Blockchain for Command Control

    The Aeternum botnet loader has been identified as using Polygon smart contracts for its command-and-control (C2) operations, moving away from traditional centralized servers. This shift complicates efforts by…

    9 articles · Updated February 26, 2026
  • Shift in Ransomware Tactics Targeting Cloud Assets

    Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…

    56 articles · Updated November 19, 2025
  • MIT Sloan Withdraws AI Ransomware Paper After Criticism

    MIT Sloan has withdrawn a working paper that claimed 80% of ransomware attacks are driven by AI after facing criticism from cybersecurity experts, including Kevin Beaumont and Marcus Hutchins. The paper, co-authored…

    3 articles · Updated November 3, 2025

Recent Intelligence Reports

  • 003 — attack.mitre.org · July 23, 2026
  • 002 — attack.mitre.org · July 23, 2026
  • T1620 — attack.mitre.org · July 23, 2026
  • 002 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • Hackers claim Deutsche Bank data breach, internal data affected — Cybernews · July 7, 2026
  • 012 — attack.mitre.org · July 1, 2026

CVSS v3.1 Breakdown