C&CMembers
C&C

Two Ghost Payloads Blind Analysts as Emotet Relay Cluster Holds Steady

Two new Emotet file samples carry zero VirusTotal enrichment — no file type, no detections, no behavioural data — while the campaign's WordPress-relay backbone and 89-day Let's Encrypt certificate rotation pattern remain entirely unchanged. The payload layer has rotated; the infrastructure has not, and the detection gap has widened.

Jun 14, 2026, 02:57 (UTC+9)Last seenJun 21, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC11RegionsRO

Since CTX Team's earlier coverage of this Emotet C2 cluster — documented in the prior article tracking the campaign's 89-day Let's Encrypt rotation pattern — two new file samples have entered the payload layer with zero VirusTotal enrichment: no file type, no detection ratio, no behavioural tags, no signer data. The infrastructure they connect to is unchanged and already fingerprinted. The payloads themselves are, at this moment, analytically invisible.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence