APTMembers
APT

Old Emotet Macro Pairs With Barely-Flagged New Infrastructure

A trojan.w97m/emotet Word document with anti-sandbox stalling and an 8/8 malicious sandbox consensus is riding alongside two freshly-certificated domains that detection engines have barely touched. The malware is six years old and well-signatured; the web infrastructure around it is new, thinly-flagged, and only loosely linked by a matching 89-day certificate cadence.

Jul 23, 2026, 21:33 (UTC+9)Last seenJul 23, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC11RegionsUS

A Word document flagged trojan.w97m/emotet doesn't just drop a payload — it stalls first. Sandbox tags on the sample read like a checklist for frustrating automated analysis: auto-open, detect-debug-environment, long-sleeps, calls-wmi. Put together, they describe a VBA macro that fires the instant the document opens [T1204.002], then deliberately pauses and probes its environment for signs of virtualization or debugging before doing anything else [T1497].

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence