APTMembers
APT

Emotet's Canadian Campaign Hides Behind Three-Layer Evasion Stack

A 141 KB Word document targeting Canadian organisations conceals a sophisticated infrastructure chain combining Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated C2 node on a previously uncatalogued Hong Kong ASN. Each layer is engineered to defeat a distinct class of network-based blocking, signalling an operator prioritising infrastructure longevity over delivery volume.

Jun 28, 2026, 17:04 (UTC+9)Last seenJun 28, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC12RegionsCA

A 141-kilobyte Word document circulating in phishing email against Canadian targets carries more infrastructure engineering behind it than its modest file size suggests. The malicious document — an Emotet e2 epoch loader first submitted to VirusTotal on 15 October 2020 and still active in this campaign — sits at the front end of a three-layer hosting architecture that combines Cloudflare origin-masking, automated 89-day TLS certificate rotation, and a dedicated command-and-control node…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence