Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- Emotet - S0367
- Source confidence
- Not reported
- Observed
- 2023-03-22 19:07 UTC
- Retrieved
- 2026-10-08 04:36 UTC
Name of ATT&CK software | [Emotet](https://attack.mitre.org/software/S0367) is a modular malware variant which is primarily used as a downloader for other malware variants such as [TrickBot](https://attack.mitre.org/software/S0266) and [IcedID](https://attack.mitre.org/software/S0483). Emotet first emerged in June 2014 and has been primarily used to target the banking sector. (Citation: Trend Micr
2023/03/emotet-switches-to-onenote.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.