Emotet is dead, long live Emotet

No ratings

Presented at RootedCON 2020 by

Emotet re-emerged in late 2016 as a malware distribution botnet, after going quiet for a while. Since then, it continues to steal credentials and use compromised accounts to carry out campaigns. In the last year, we have seen how its social engineering techniques have improved dramatically, making them even more credible to its victims. Cybercriminal groups, including those operating Trickbot and Dridex are using Emotet to spread their malware, which in some cases has been used to compromise large organizations and install targeted ransomware such as Ryuk and BitPaymer. This talk will offer detail on Emotet's activity in the past year, providing analysis of important campaigns and dive into its relationships with the groups behind Trickbot and Dridex