APTMembers
APT

A 2019 Emotet Invoice Lure Resurfaces With Newly Certified Dormant Domains

A German/Polish invoice-themed Word document tied to Emotet's 2019 malspam wave has resurfaced in telemetry alongside four domains registered between 1997 and 2026. Three sat dormant for a decade or more before recently receiving fresh TLS certificates, suggesting old crimeware infrastructure being reactivated rather than a newly built campaign.

Sep 5, 2026, 06:28 (UTC+9)Last seenSep 5, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC14RegionsDE

A Word document dressed as a German electricity invoice and a Polish payment notice has resurfaced in telemetry alongside four domains whose registration dates read like a timeline of the internet itself — 1997, 2004, 2014, and 2026. Three of those domains sat dormant for a decade or more before anyone bothered to issue them a fresh TLS certificate; the fourth, registered this year, doesn't even carry its own certificate, borrowing a wildcard from a shared hosting platform instead.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence