
After a 10-month-long hiatus, the notorious Emotet botnet is once again exhibiting signs of steady growth worldwide. According to reports, the new variant of the malware has already infected 130,000 systems in 179 countries and is getting stronger daily via phishing campaigns beginning in January 2022.
After infecting over 1.6 million devices globally and acting as a conduit for cybercriminals to install other types of malware onto compromised systems, Emotet activities stopped in late January 2021 with a coordinated law enforcement operation dubbed “Ladybird” by Europol and Eurojust.
However, the malware officially resurfaced in November 2021, using TrickBot as a delivery vehicle, allegedly designed by the Conti ransomware gang to gain initial access to corporate networks. After the initial infection, Emotet goes straight to dropping the Cobalt Strike pen-testing tool for quick remote access to networks.
The aggregation of bots didn’t start in earnest until January 2022, according to researchers at Black Lotus Labs, who dug deeper into Emotet’s “Epoch 3” to identify new features and map current distribution patterns. The researchers found that new elliptic curve cryptography (ECC) replaces the RSA encryption scheme for network traffic protection and validation in the new Emotet variant.
Another new feature is the ability to collect additional system information from compromised machines in addition to a list of running processes. Additionally, the malware authors have added more data-gathering capabilities for better system profiling, whereas Emotet previously only returned a list of running processes.
The botnet infrastructure of Emotet is said to consist of nearly 200 different command-and-control (C2) servers, with most of the domains located in the U.S., Germany, France, Brazil, Thailand, Singapore, Indonesia, Canada, the U.K., and India. This number is steadily increasing, and the average number of days of activity for C2s is presently 29.
The researchers said that the infected bots are heavily concentrated in Asia, chiefly Japan, India, Indonesia, and Thailand, followed by South Africa, Mexico, the U.S., China, Brazil, and Italy, due to the large population of vulnerable or outdated Windows hosts in the regions.
In December, as Bleeping Computer reported, Emotet used a Windows AppX Installer spoofing vulnerability to install apps from a remote source on the host. Microsoft patched the issue, which was identified as CVE-2021-43890, in December 2021 Path Tuesday. However, the software giant decided to disable the abused MSIX handler due to the slow upgrade uptick vs. the projected benefits of keeping it. Still, the researchers warned that Emotet could infect pirated Windows copies that have purposefully cut off their connection to Microsoft update servers.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543