
Old Macro-to-PowerShell Emotet Chain Still Fools Every Sandbox
A macro-laced Word document targeting US education and research institutions triggers unanimous malicious verdicts across three sandboxes and 43 of 75 antivirus engines. The well-documented Emotet downloader chain still clears email gateways years after its pattern became one of the industry's most-studied threats.
A macro-laced Word document circulating against United States education and research targets is producing a rare thing in modern detection telemetry: unanimous agreement. All three sandboxes that processed the sample — C2AE, ReaQta-Hive, and BitDam ATP — return a "malicious" verdict, and 43 of 75 antivirus engines flag the file outright.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read