Botnet that knows your name and quotes your email is back with new tricks

IT’S BA-ACK! —

Quoting Herman Melville is only one of Emotet’s latest innovations.


Botnet that knows your name and quotes your email is back with new tricks

Getty Images

Widely regarded as one of the Internet’s top threats, the Emotet botnet has returned after a months-long hiatus—and it has some new tricks.

Last week, Emotet appeared for the first time this year after a four-month hiatus. It returned with its trademark activity—a wave of malicious spam messages that appear to come from a known contact, address the recipient by name, and seem to be replying to an existing email thread. When Emotet has returned from previous breaks, it has brought new techniques designed to evade endpoint security products and to trick users into clicking on links or enabling dangerous macros in attached Microsoft Office documents. Last week’s resumption of activity was no different.

A malicious email sent last Tuesday, for instance, attached a Word document that had a massive amount of extraneous data added to the end. As a result, the file was more than 500MB in size, big enough to prevent some security products from being able to scan the contents. This technique, known as binary padding or file pumping, works by adding zeros to the end of the document. In the event someone is tricked into enabling the macro, the malicious Windows DLL file that’s delivered is also pumped, causing it to mushroom from 616kB to 548.1MB, researchers from security firm Trend Micro said on Monday.

Another evasion trick spotted in the attached document: excerpts from the Herman Melville classic novel Moby Dick, which appear in a white font over a white page so the text isn’t readable. Some security products automatically flag Microsoft Office files containing just a macro and an image. The invisible text is designed to evade such software while not arousing the suspicion of the target.

Deep Instinct

When opened, the Word documents present a graphic that says the content can’t be accessed unless the user clicks the “enable content” button. Last year, Microsoft began disabling macros downloaded from the Internet by default.

The graphic that appears immediately after opening a malicious Word document. It says the content can't be accessed unless the

Enlarge / The graphic that appears immediately after opening a malicious Word document. It says the content can’t be accessed unless the “enable content” button is clicked.

Trend Micro

Clicking the “enable content” button undoes that default and allows the macro to run. The macro causes Office to download a .zip file from a legitimate website that has been hacked. Office will then unzip the archive file and execute the inflated Emotet DLL that infects the device.

Once it has infected a victim’s device, the malware pilfers passwords and other sensitive data and uses the device to send malicious spam to other users. The malware can also download additional malware such as the Ryuk ransomware or the TrickBot malware. The infection chain looks like this:

Trend Micro

The attention to detail seen in this latest revival is signature Emotet behavior. For years, the botnet has painstakingly copied received email conversations from infected machines and embedded them into malicious spam sent to other parties in the thread. By following up on an email from someone the target has communicated with in the past, the malicious spam message stands a better chance of going undetected. Emotet can also gain access to Wi-Fi networks and infect connected devices.

With the return of Emotet, people should be on the lookout for malicious emails, even if they appear to come from trusted sources, call the target by name, and include previously sent and received emails. There is rarely a good reason for enabling macros in documents sent by email. People should refuse to allow them to run without first communicating with the sender by phone, instant message, or another non-email medium.

Countries hit the hardest in the latest Emotet run are European, Asian Pacific, and Latin American.

Read More
Dan Goodin

Latest

Brendan Sorsby’s football career may rightfully be put on ice after Browns appear uninterested

Bullet point summary by AI Brendan Sorsby's professional football career is in serious jeopardy after a major NFL team publicly distanced themselves from him. Cleveland Browns coach Todd Monken ruled out drafting the Texas Tech QB in the supplemental draft due to his college gambling violations. NFL teams are drawing a hard line on off-field

DeSean Jackson Calls Michael Vick’s Support a “Blessing” After Breakthrough HBCU Season

DeSean Jackson’s appointment as the head coach of the Delaware State Hornets caught college football unawares. But what was even more shocking was how he had a winning season with almost no coaching experience. As he talks about his mind-blowing debut season, Jackson mentions former teammate and current rival Michael Vick as a “blessing.” Watch

‘Don’t Think Anyone Wants To Be In Cleveland:’ Cam Heyward Reacts To Myles Garrett Trade

Cam Heyward’s never directly went up against Myles Garrett, which may be why he “could care less” that the former Cleveland Browns pass rusher is no longer in the division. On his Not Just Football podcast, Heyward reacted to the Browns trading Garrett to the Los Angeles Rams. “I think Aaron [Rodgers]’s definitely happy to

2027 NFL Draft Prospect Interview: Braedon Hellinger, LB, Aurora University

Meet Braedon Hellinger, a 2027 NFL Draft prospect. Discover his journey, passion for football, and personal insights. Name: Braedon Hellinger Position: LB College: Aurora University Height: 6’ 0” Weight: 215 lbs X: @23braedon23 Instagram: @2braedon2 What made you decide you wanted to be a football player? What made me decide to be a football player

Newsletter

Don't miss

Brendan Sorsby’s football career may rightfully be put on ice after Browns appear uninterested

Bullet point summary by AI Brendan Sorsby's professional football career is in serious jeopardy after a major NFL team publicly distanced themselves from him. Cleveland Browns coach Todd Monken ruled out drafting the Texas Tech QB in the supplemental draft due to his college gambling violations. NFL teams are drawing a hard line on off-field

DeSean Jackson Calls Michael Vick’s Support a “Blessing” After Breakthrough HBCU Season

DeSean Jackson’s appointment as the head coach of the Delaware State Hornets caught college football unawares. But what was even more shocking was how he had a winning season with almost no coaching experience. As he talks about his mind-blowing debut season, Jackson mentions former teammate and current rival Michael Vick as a “blessing.” Watch

‘Don’t Think Anyone Wants To Be In Cleveland:’ Cam Heyward Reacts To Myles Garrett Trade

Cam Heyward’s never directly went up against Myles Garrett, which may be why he “could care less” that the former Cleveland Browns pass rusher is no longer in the division. On his Not Just Football podcast, Heyward reacted to the Browns trading Garrett to the Los Angeles Rams. “I think Aaron [Rodgers]’s definitely happy to

2027 NFL Draft Prospect Interview: Braedon Hellinger, LB, Aurora University

Meet Braedon Hellinger, a 2027 NFL Draft prospect. Discover his journey, passion for football, and personal insights. Name: Braedon Hellinger Position: LB College: Aurora University Height: 6’ 0” Weight: 215 lbs X: @23braedon23 Instagram: @2braedon2 What made you decide you wanted to be a football player? What made me decide to be a football player

Badgers Beat Blue Bloods to Land Intriguing CB Prospect from California

Wisconsin football's first official visit weekend is the gift that keeps on giving. Just two days after the Badgers secured commitments from four-star wideout Jai Jones and three-star linebacker Nathan Jones, another high-priority target has pledged to Wisconsin after its first big recruiting weekend of the summer. Three-star cornerback Royalton Allen from Hesperia, California became

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they