WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Experiencing an Inbox Influx? – It’s Probably Emotet, Again
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Experiencing an Inbox Influx? – It’s Probably Emotet, Again

Author: Jennifer Walker

Created: Tuesday, July 21, 2020 - 15:21

Categories: Cybersecurity

Last week, researchers observed Emotet awake from its 160 day slumber. The “public cyber enemy,” as Malwarebytes is calling it, seemed to warm-up as it began lightly populating inboxes on July 13. But by July 17, the malspam onslaught commenced with nearly a quarter million messages. Emotet usually emerges out of hibernation with a new tactic in its arsenal, but so far nothing remarkable. It seems to be up to its old tricks, but that does not make it any less problematic as Emotet is used to spread additional malware, such as TrickBot and ransomware, including Ryuk. According to Proofpoint, the messages contain malicious Microsoft Word attachments or URLs linking to malicious Word documents hosted on compromised WordPress websites. In addition to frequent prior reporting and briefings on Emotet, Paul Scott, Director of Threat Research at Perch Security recently provided a comprehensive background for members during WaterISAC’s Water Sector Cyber Threat Briefing on May 27. Additionally, members are encouraged to review the MITRE ATT&CK Framework to understand additional techniques used by Emotet for better network defense against this familiar foe. Read more about Emotet’s awakening at Proofpoint

Related Resources

Members Only

(TLP:AMBER) April 22, 2026 WaterISAC Cyber Resilience Briefing

Apr 23, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) WaterISAC Notification – CISA Issues Cyber Alert ​​for Supply Chain Compromise Impacting Axios Node Package Manager​

Apr 20, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated April 17, 2026)

Apr 17, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar