Emotet: The Malware Loader Behind Ransomware
Emotet is the malware loader behind most ransomware attacks, spreading via phishing emails. Its 2025 successors PikaBot and DarkGate abuse Microsoft Teams.
What Is This Threat?
A malware loader is a small program whose sole job is to silently infect your device and then download and install a second, more dangerous payload β typically ransomware, a banking trojan, or a remote access tool. You rarely notice the loader itself; you only see the damage the payload causes.
Emotet (active 2014β2023) was the world's most dangerous malware loader, described by Europol as "the world's most dangerous malware" at its peak. It infected millions of devices by hiding inside Microsoft Office documents sent via realistic-looking phishing emails. Once installed, it rented access to infected machines to other criminal groups β a business model that effectively industrialised cybercrime.
Though Emotet itself is largely dormant since late 2023, the infection model it invented lives on in its successors, which are actively causing major breaches in 2025β2026.
How Emotet Worked (and How Its Successors Work Today)
Classic Emotet chain (2018β2022):
2022 Pivot β Microsoft Kills Macros:
In July 2022, Microsoft disabled VBA macros in Office documents downloaded from the internet by default. This destroyed Emotet's primary delivery method almost overnight.
2023β2026 Evolution β New Loaders, New Vectors:
Rather than disappear, the criminal ecosystem adapted. The successors active in 2025β2026:
.one) attachments. Used to deliver Cobalt Strike and ransomware to corporate targets.2026 Threat: AI-Enhanced Delivery:
Malware loaders in 2026 increasingly use AI-generated phishing content β emails with perfect grammar in the target's language, personalised with details scraped from LinkedIn, and sent at psychologically optimal times. Traditional spam filters trained to catch poorly written emails are less effective against these.
Real-World Impact
Red Flags
.one) or HTML attachment in an email, even from a known sender.How to Protect Yourself
- Never enable macros in Office documents you received via email β Microsoft disabled them by default for good reason; re-enabling them is almost always a social engineering trap
- Block external Microsoft Teams messages from unknown domains in your tenant settings, or require admin approval β DarkGate exploits the default open configuration
- Deploy an email security gateway that sandboxes attachments (OneNote, ZIP, PDF) before delivery β modern loaders hide inside file types that basic filters miss
- Keep Windows, Office, and browser extensions fully patched β many loaders exploit known vulnerabilities in outdated software as a fallback entry point
- Use endpoint detection and response (EDR) that monitors process behaviour, not just file signatures β loaders are designed to evade signature-based antivirus
What to Do If Affected
- 1.If you enabled macros or opened a suspicious file, disconnect from the network immediately and report to your IT team β the loader may still be in the download phase
- 2.Run a full offline antivirus scan using a bootable rescue disk (ESET, Kaspersky, Bitdefender all offer free rescue ISOs) β Emotet variants hide from live OS scans
- 3.Change all passwords from a clean, uninfected device β Emotet and its successors harvest stored credentials from browsers and email clients
- 4.Report the phishing email to your national cybersecurity authority and the email provider so the campaign can be disrupted (Austria: cert.at, Germany: BSI, Ukraine: CERT-UA)
- 5.If inside a corporate network, assume lateral spread has occurred β audit all machines that communicated with the infected device in the 48 hours prior to detection