
Five-Year-Old Emotet Macro Downloader Resurfaces in 2026 Tracking Window
A Word document first seen on VirusTotal in 2020 still auto-opens, drops, and runs a PowerShell downloader, scoring 44/77 detections and a 3-for-3 sandbox-malicious verdict. It now appears inside a tracking window stretching into 2026, bundled with two Let's Encrypt-certified domains and an isolated Singapore VPS.
A Word document that first surfaced on VirusTotal in October 2020 is still doing exactly what it was built to do: open itself, drop a second file, and run it. The sample — internally named Attachment-5598.doc, a naming pattern consistent with an email-lure delivery method [T1566.001] though no delivery URL or mail header sits in this record to confirm that path — carries the tags "auto open," "creates OLE objects," "contains office macros," and "runs a file it drops to disk." That is not a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read