APTMembers
APT

Old Macro-to-PowerShell Emotet Chain Still Fools Every Sandbox

A macro-laced Word document targeting US education and research institutions triggers unanimous malicious verdicts across three sandboxes and 43 of 75 antivirus engines. The well-documented Emotet downloader chain still clears email gateways years after its pattern became one of the industry's most-studied threats.

Aug 7, 2026, 06:05 (UTC+9)Last seenAug 7, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC11RegionsUS

A macro-laced Word document circulating against United States education and research targets is producing a rare thing in modern detection telemetry: unanimous agreement. All three sandboxes that processed the sample — C2AE, ReaQta-Hive, and BitDam ATP — return a "malicious" verdict, and 43 of 75 antivirus engines flag the file outright.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence