
Emotet's Canadian Campaign Hides Behind Three-Layer Evasion Stack
A 141 KB Word document targeting Canadian organisations conceals a sophisticated infrastructure chain combining Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated C2 node on a previously uncatalogued Hong Kong ASN. Each layer is engineered to defeat a distinct class of network-based blocking, signalling an operator prioritising infrastructure longevity over delivery volume.
A 141-kilobyte Word document circulating in phishing email against Canadian targets carries more infrastructure engineering behind it than its modest file size suggests. The malicious document — an Emotet e2 epoch loader first submitted to VirusTotal on 15 October 2020 and still active in this campaign — sits at the front end of a three-layer hosting architecture that combines Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated command-and-control node…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read