LIVE: New phishing campaigns targeting mobile users β€”View latest threats β†’

Back to Threats
Critical🦠 MalwareNEW

Emotet: The Malware Loader Behind Ransomware

Emotet is the malware loader behind most ransomware attacks, spreading via phishing emails. Its 2025 successors PikaBot and DarkGate abuse Microsoft Teams.

Published: 15 June 2026Last updated: 20 May 2026

What Is This Threat?

A malware loader is a small program whose sole job is to silently infect your device and then download and install a second, more dangerous payload β€” typically ransomware, a banking trojan, or a remote access tool. You rarely notice the loader itself; you only see the damage the payload causes.

Emotet (active 2014–2023) was the world's most dangerous malware loader, described by Europol as "the world's most dangerous malware" at its peak. It infected millions of devices by hiding inside Microsoft Office documents sent via realistic-looking phishing emails. Once installed, it rented access to infected machines to other criminal groups β€” a business model that effectively industrialised cybercrime.

Though Emotet itself is largely dormant since late 2023, the infection model it invented lives on in its successors, which are actively causing major breaches in 2025–2026.

How Emotet Worked (and How Its Successors Work Today)

Classic Emotet chain (2018–2022):

  • A convincing phishing email arrives β€” often a reply to a real stolen email thread ("thread hijacking"), making it appear legitimate.
  • The attached Word document instructs you to "Enable Macros" to view the content.
  • Enabling macros runs the Emotet loader silently in the background.
  • Emotet connects to its command-and-control servers, downloads secondary payloads (TrickBot, Qakbot), and emails itself to everyone in your contacts.
  • Secondary payload harvests banking credentials or deploys ransomware (Ryuk, Conti).
  • 2022 Pivot β€” Microsoft Kills Macros:

    In July 2022, Microsoft disabled VBA macros in Office documents downloaded from the internet by default. This destroyed Emotet's primary delivery method almost overnight.

    2023–2026 Evolution β€” New Loaders, New Vectors:

    Rather than disappear, the criminal ecosystem adapted. The successors active in 2025–2026:

  • PikaBot (2023–2026): Emerged as a direct spiritual successor to Emotet. Spreads via email with ZIP archives, PDF files, and OneNote (.one) attachments. Used to deliver Cobalt Strike and ransomware to corporate targets.
  • Latrodectus (2024–2026): Believed to be developed by the same threat actors behind Emotet (TA577/TA578). Delivered via malicious JavaScript files in email attachments. More sophisticated evasion than Emotet.
  • DarkGate (2023–2026): Exploits Microsoft Teams, Skype, and Slack as delivery channels β€” attackers message targets directly via compromised corporate accounts or external guest invitations, bypassing email security filters entirely. Also spreads via malvertising (malicious Google ads).
  • QakBot / Qbot (resurfaced 2024): Taken down by the FBI in August 2023 ("Operation Duck Hunt"), but the operators rebuilt and relaunched within months, targeting financial institutions.
  • 2026 Threat: AI-Enhanced Delivery:

    Malware loaders in 2026 increasingly use AI-generated phishing content β€” emails with perfect grammar in the target's language, personalised with details scraped from LinkedIn, and sent at psychologically optimal times. Traditional spam filters trained to catch poorly written emails are less effective against these.

    Real-World Impact

  • Emotet takedown (January 2021 β€” Operation Ladybird): Europol and Eurojust coordinated law enforcement across 8 countries to seize Emotet's infrastructure. Emotet returned 10 months later in November 2021.
  • DarkGate via Microsoft Teams (2023–2024): Microsoft reported that attackers using Teams external access sent malware-laden OneNote files to over 40 unique global organisations in a single campaign.
  • PikaBot in 2024: Cisco Talos identified PikaBot as the top malware loader replacing Emotet's role in the QakBot vacuum, used in high-volume email campaigns delivering Black Basta ransomware.
  • QakBot resurgence (December 2023): Just 3 months after the FBI's Operation Duck Hunt, QakBot operators sent a new phishing campaign targeting the hospitality industry.
  • Red Flags

  • An email asking you to "Enable Content" or "Enable Macros" in an Office document.
  • A Microsoft Teams message from an external account containing an attachment or a link to download a file.
  • An unexpected OneNote (.one) or HTML attachment in an email, even from a known sender.
  • Antivirus silently disabled or security tools stopped running without explanation.
  • Unusual outbound network connections to unknown IPs at unusual hours.
  • How to Protect Yourself

    • Never enable macros in Office documents you received via email β€” Microsoft disabled them by default for good reason; re-enabling them is almost always a social engineering trap
    • Block external Microsoft Teams messages from unknown domains in your tenant settings, or require admin approval β€” DarkGate exploits the default open configuration
    • Deploy an email security gateway that sandboxes attachments (OneNote, ZIP, PDF) before delivery β€” modern loaders hide inside file types that basic filters miss
    • Keep Windows, Office, and browser extensions fully patched β€” many loaders exploit known vulnerabilities in outdated software as a fallback entry point
    • Use endpoint detection and response (EDR) that monitors process behaviour, not just file signatures β€” loaders are designed to evade signature-based antivirus

    What to Do If Affected

    1. 1.If you enabled macros or opened a suspicious file, disconnect from the network immediately and report to your IT team β€” the loader may still be in the download phase
    2. 2.Run a full offline antivirus scan using a bootable rescue disk (ESET, Kaspersky, Bitdefender all offer free rescue ISOs) β€” Emotet variants hide from live OS scans
    3. 3.Change all passwords from a clean, uninfected device β€” Emotet and its successors harvest stored credentials from browsers and email clients
    4. 4.Report the phishing email to your national cybersecurity authority and the email provider so the campaign can be disrupted (Austria: cert.at, Germany: BSI, Ukraine: CERT-UA)
    5. 5.If inside a corporate network, assume lateral spread has occurred β€” audit all machines that communicated with the infected device in the 48 hours prior to detection
    #Emotet#malware loader#botnet#PikaBot#DarkGate#Latrodectus#Microsoft Teams#initial access broker#2026