Global security desk · updated coverage of threats, exploits & breaches

Emotet returns: fresh variant spotted after global takedown

Threat analysts have identified a renewed wave of Emotet activity targeting organisations across multiple regions, including Australia, signalling that the botnet infrastructure dismantled in early 2024 has been reconstituted. The new samples bear hallmarks of the original codebase but include updated modules designed to evade detection and persist on compromised Windows hosts.

For Australian IT teams, the reappearance is a reminder that high-profile law enforcement actions rarely spell the end of a mature malware operation. Emotet's operators have historically resurfaced within months of coordinated takedowns, and the latest iteration appears focused on regaining footholds in enterprise networks where defenders may have grown complacent.

Resurgence of the botnet infrastructure

Samples collected by independent researchers and shared through hacking coverage feeds show communication with updated command-and-control servers, many of which are hosted on bulletproof providers and rotated every few days. The new variant uses XOR-based string obfuscation layered with custom packing, making static signatures far less reliable than they were in earlier campaigns.

Telemetry from sandbox providers indicates that the loader checks for virtualisation artefacts before executing its main payload, a behaviour consistent with Emotet's long-standing anti-analysis tradition. Once the malware confirms it is running on a genuine endpoint, it establishes persistence through scheduled tasks and, in some cases, leverages Windows System Restore Points as a stashing location for secondary payloads. Defenders investigating suspicious activity should correlate restore point creation timestamps with other suspicious events during triage.

The financial sector appears particularly exposed, with several Australian banks confirming they have observed credential harvesting attempts tied to the new infrastructure. Industry partners are sharing samples through the Financial Services Information Sharing and Analysis Center, which has begun circulating technical indicators to its Australian members.

Technical shifts in the new build

While the core DLL loader remains recognisable, several modules have been rewritten or replaced. The new build drops a lightweight downloader first, fetches the main payload in stages, and uses HTTPS over non-standard ports to blend with legitimate traffic. Cobalt Strike beacons have been replaced in some samples with a custom implant that communicates over WebSocket channels.

Analysis of the unpacked binary shows strings referencing legitimate Australian banking domains, suggesting the operators have prepared tailored injects rather than relying on generic web inject kits. Australian organisations with mature threat hunting programmes should treat any match on the WebSocket-based command-and-control user-agent strings as a high-confidence indicator requiring immediate investigation.

Key technical differences observed in the latest samples include:

These shifts suggest the developers have invested time in rebuilding parts of the kit rather than simply repacking old binaries. Australian SOC teams operating 24/7 monitoring in Brisbane, Melbourne, and Sydney have reported an uptick in related alert volume over the past two weeks, correlating with the broader global trend.

Australian exposure and targeting patterns

Local data suggests Australian organisations are once again being targeted, particularly in the professional services, manufacturing, and higher education sectors. The Australian Cyber Security Centre has published refreshed advisories urging businesses to revisit patch cycles and email filtering rules. Phishing lures observed in the country frequently reference the Australian Taxation Office, myGov, and state health authorities, exploiting the public's familiarity with those brands.

The timing is significant. Many finance teams in Sydney and Melbourne are processing end-of-financial-year paperwork, and the increase in legitimate ATO-themed correspondence creates cover for malicious attachments. Several managed service providers in Perth have reported clients receiving weaponised invoices disguised as supplier statements, a tactic that has previously proven effective against smaller accounting practices.

Australia's Notifiable Data Breaches scheme means that any organisation turning over more than AUD 3 million and experiencing a likely eligible breach must notify the Office of the Australian Information Commissioner. That regulatory backdrop raises the stakes for local entities that might otherwise treat an Emotet infection as a routine cleanup job.

Small and medium-sized businesses across regional Australia remain particularly vulnerable, often running legacy infrastructure with limited monitoring capability. Several councils in regional New South Wales and Queensland have publicly acknowledged recent attempts, underscoring that the threat is not limited to the largest metropolitan organisations.

Distribution tactics and payload delivery

The latest campaign relies heavily on threaded email conversations, where attackers reply to existing threads with malicious attachments or links. This approach leverages the trust built up over weeks or months of legitimate correspondence, making the malicious message far more convincing. Common attachment types include password-protected ZIP files, Excel documents with macro luring, and OneNote files embedding external templates.

Once a user enables macros or opens the lure document, the dropper reaches out to its command server, downloads the main module, and begins lateral movement using harvested credentials. SMB and WinRM remain the preferred propagation methods, with RDP used sparingly to avoid triggering network anomaly detection rules commonly seen in mature Australian enterprise environments.

Researchers have also observed the use of compromised legitimate websites as redirector chains, particularly small business sites running outdated content management systems. Hosting providers in Australia have been notified of several compromised domains, though takedown timelines remain inconsistent across the ecosystem.

Secondary payloads delivered through this campaign have included credential stealers, banking trojans tailored to target Australian banking portals, and ransomware affiliates operating on a leak-site model. The banking overlays have specifically targeted NAB, CommBank, and ANZ login flows, indicating reconnaissance tailored to local conditions rather than opportunistic global deployment.

Defensive measures for local organisations

Practical steps that Australian IT and security teams can take right now focus on reducing the blast radius of any successful intrusion. Emotet thrives in environments where credential reuse is common, where email gateways do not strip macro-enabled documents, and where lateral movement is unrestricted by network segmentation.

For incident responders, understanding the role of restore points is critical, as the new variant occasionally leverages these for persistence. Detailed guidance on handling malware in restore points is available for teams undertaking clean-up operations.

Recommended actions include:

Organisations should also verify that offline backups exist and are tested, since ransomware affiliates associated with this campaign have shown a willingness to encrypt within 48 hours of initial access. For businesses operating hybrid environments across Australian data centres and hyperscaler regions, segmenting identity infrastructure from production workloads is a worthwhile near-term investment.

Indicators worth monitoring

Detection teams hunting this campaign should pay attention to specific behaviours that distinguish the new build from commodity malware. Scheduled task creation referencing PowerShell, unexpected svchost.exe spawned by Word or Excel, and outbound WebSocket connections from user workstations are all worth investigating with higher priority than typical alert triage.

Microsoft has confirmed that recent versions of Defender for Endpoint trigger on the new dropper behaviour, but signature coverage alone is not sufficient. Hunting queries should focus on the timeframe immediately after a user opens a document from an external sender, particularly when that document originated from a thread hijacking scenario. Splunk, Elastic, and Sentinel customers in Australia have shared Sigma rules that detect the obfuscated PowerShell loader pattern associated with this build.

Network defenders should also review proxy logs for unusual long-lived outbound connections, as the WebSocket beacon maintains persistence through keepalive packets. A spike in outbound traffic from a finance or HR subnet, even at modest volumes, warrants a closer look given the campaign's deliberate low-and-slow approach to command-and-control.

Broader industry response and outlook

International coordination that dismantled Emotet in 2024 involved agencies including the FBI, the Dutch National Police, and partners across Europe. Australian federal authorities participated through intelligence sharing, though the domestic role was less public. The recurrence highlights the difficulty of permanently disabling malware-as-a-service operations, especially when developers retain access to source code and operator relationships.

Looking ahead, analysts expect the new variant to expand its targeting over the coming quarter, with potential shifts toward Microsoft Teams-based phishing and abuse of cloud file-sharing links. Australian organisations that have invested in the Essential Eight maturity model are likely better positioned than those that have not, but the threat remains serious for any environment where email remains the primary ingress vector and where credentials are not adequately protected.

Defenders should also expect increased activity around major Australian events and holidays, when finance and HR staff are processing seasonal correspondence. The pattern mirrors previous Emotet waves that timed spam surges around Black Friday, end-of-financial-year, and pre-Christmas periods to maximise the chance of an opportunistic click.