A Comprehensive Look at Emotet’s Fall 2022 Return
released on 2022-11-16 @ 01:03:20 PM
TA542, an actor that distributes Emotet malware, has once again returned from an extensive break from delivering malicious emails. The actor was absent from the landscape for nearly four months, last seen on July 13, 2022, before returning on November 2, 2022.
The activity is quite similar to July campaigns and many previously observed tactics remain the same, however, there have been some changes and improvements such as new Excel attachment visual lures, changes to Emotet binary, a new version of the IcedID loader dropped by Emotet and the use of Bumblebee loader in addition to IcedID.