Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Emotet Tests New Delivery Techniques
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > Emotet Tests New Delivery Techniques
Cyber

Emotet Tests New Delivery Techniques

Editorial Desk
Last updated: June 18, 2022 12:21 am
Editorial Desk
Share
SHARE

Cybersecurity researchers at Proofpoint have today published new research revealing brand new tactics used to distribute the notorious Emotet botnet, indicating that the cybercriminal group (TA542) is testing new attack techniques on a small scale before adopting them for larger volume campaigns.

In recent activity from April 2022, the TA542 group displayed a number of unusual tactics:

  • The low-volume nature of the activity –Typically Emotet distributes high-volume email campaigns to many targets globally. 

    The use of OneDrive URLs – Typically Emotet delivers Microsoft Office attachments or URLs (hosted on compromised sites) linking to Office files. 
  • The use of XLL files – Typically, Emotet uses Microsoft Excel or Word documents containing VBA or XL4 macros.

It is notable that TA542 is interested in new techniques that do not rely on macro-enabled documents as Microsoft is making it increasingly difficult for threat actors to use macros as an infection vector.

Key Findings

• Proofpoint identified low-volume Emotet activity that drastically differed from typical  Emotet threat behaviors. 

• The activity occurred while Emotet was on a “spring break,” not conducting its typical  high volume threat campaigns. The threat actor has since resumed its typical activity.

• Proofpoint assesses that the threat group distributing Emotet is likely testing new  tactics, techniques, and procedures (TTPs) on a small scale before adopting them in  broader campaigns or to deploy them in parallel with the broad campaigns.

• The messages contained OneDrive URLs that hosted a zip archive containing XLL files  dropping Emotet malware.  

• This activity is attributed to TA542.  

Overview 

Emotet is a prolific botnet and trojan that targets Windows platforms to distribute follow-on  malware. It was considered one of the most prolific cybercriminal threats before its disruption  by global law enforcement in January 2021.  

In November 2021, 10 months after its disappearance from the threat landscape, Proofpoint  observed a reemergence of this notorious botnet, and since then, the group associated with  Emotet, TA542, has targeted thousands of customers with tens of thousands of messages in  

multiple geographic regions. In some cases, the message volume reaches over one million per  campaign.  

However, the new activity observed by Proofpoint is a departure from their typical behaviors  and indicates the group is testing new attack techniques on a small scale before adopting them  for larger volume campaigns. Alternatively, these new TTPs may indicate that TA542 may now  be engaged in more selective and limited attacks in parallel to the typical massive scale email  campaigns. 

Activity Details 

Proofpoint detected a low volume of emails distributing Emotet. The sender emails appeared to  be compromised. The emails were not sent by the Emotet spam module. The subjects were  simple and contained one word such as “Salary”. The email bodies contained only OneDrive  URLs and no other content. The OneDrive URLs hosted zip files containing Microsoft Excel Add in (XLL) files. 

The zip archives and XLL files used the same lures as the email subjects, such as 

“Salary_new.zip.” This particular archive contained four copies of the same XLL file with names such as “Salary_and_bonuses-04.01.2022.xll”. The XLL files, when executed, drop and run  Emotet leveraging the Epoch 4 botnet.  

Figure: Example OneDrive URL hosting a zip archive

The identified activity differs from previously observed Emotet campaigns in the following  ways: 

– The low-volume nature of the activity. Typically, Emotet distributes high-volume email  campaigns to many customers globally, with some campaigns in recent weeks hitting  one million messages total.  

– The use of OneDrive URLs. Typically, Emotet delivers Microsoft Office attachments or  URLs (hosted on compromised sites) linking to Office files.  

– The use of XLL files. Typically, Emotet uses Microsoft Excel or Word documents  containing VBA or XL4 macros. XLLs are a type of dynamic link library (DLL) file for Excel  and are designed to increase the functionality of the application. 

Nevertheless, Proofpoint analysts attribute this activity with high confidence to threat actor  TA542 because since 2014 the actor closely controlled the Emotet malware and is not rented it  to other actors.  

Additional Context 

Proofpoint observed the activity at a time when the widespread Emotet campaigns were on  pause (a “spring break”) between April 4, 2022, and April 19, 2022. Emotet has since resumed  its high-volume campaigns. Proofpoint researchers assess that while on the break, TA542 continued development and testing of new attack vectors, specifically OneDrive URLs and XLL  files, in preparation for using them on a wider scale. Alternatively, these new TTPs may indicate 

that TA542 may now be engaged in more selective and limited scale attacks in parallel to the  typical mass scale email campaigns. 

Figure: Plot of Emotet email volumes since November 2021

Additionally, it is notable that TA542 is interested in new techniques that do not rely on macro enabled documents as Microsoft is making it increasingly difficult for threat actors to use  macros as an infection vector. In February, Microsoft announced it would begin blocking Visual  Basic for Application (VBA) macros obtained from the internet by default in April. This follows  Microsoft’s announcement to disable XL4 macros in 2021. Typically, threat actors including  TA542 that use macro-enabled attachments rely on social engineering to convince a recipient  the content is trustworthy, and enabling macros is necessary to view it. 

Indicators of Compromise (IOC)

Indicator Description
https[:]//1drv[.]ms/u/s!AnTRAbuGZ8jie3V-jtcrv7-8xx0 Example URL leading to  zipped XLL
2da9fa07fef0855b4144b70639be4355507612181f9889960253f61eddaa47aa SHA256 Salary_new.zip
f83e9f85241d02046504d27a22bfc757ea6ff903e56de0a617c8d32d9f1f8411 SHA256  Salary_and_bonuses 01.01.2022.xll
8ee2296a2dc8f15b374e72c21475216e8d20d4e852509beb3cff9e454f4c28d1 SHA256 Emotet Payload  ezesqrmrsbhftab.lft

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article AML Group Anti-money laundering startup First AML opens UK doors to rush of inbound business enquiries 
Next Article Home security app How Safe Is My Place? Find Out With New Home Security App
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Proofpoint Emotet

Tech Articles

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

How some of the internet’s best independent blogs were quietly…

June 3, 2026
Why your nbn evening speeds slow down

Why Your NBN Slows Down at Night — And How To Find the Real Cause

NBN slow at night? ACCC data shows why evening speeds…

July 2, 2026
The Growing Crisis of Space junk and Debris

Space Junk Is Becoming One of the Biggest Threats to Modern Spaceflight

More than 33,000 tracked objects now orbit Earth at speeds…

May 8, 2026

Recent News

Cyber Security Absent From National Policy Debates - Tech News
Cyber

Cyber Security Absent From National Policy Debates During The Federal Election Cycle

7 Min Read
Palo Alto Networks Doubles Down on the Asia Pacific and Japan Region - Anupam Upadhyaya
Cyber

Palo Alto Networks Ramps Up Cloud Investments in Asia-Pacific To Strengthen Cybersecurity

3 Min Read
Mark Gorrie warns that Australian voters are prime targets with cyberattacks targeting voter engagement
Cyber

Australians Brace For Potential Cyberattacks Targeting Voter Engagement

3 Min Read
Cyber Criminals
Cyber

Who Are Cyber Criminals?

12 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

August, 07, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?