WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Threat Awareness – Emotet Modifying Tactics to Infect More Users
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Emotet Modifying Tactics to Infect More Users

Author: Alec Davison

Created: Tuesday, June 14, 2022 - 18:47

Categories: Cybersecurity

Threat actors behind the infamous Emotet malware are employing new sophisticated attack techniques to infect systems and networks and steal credentials. According to the cybersecurity company Deep Instinct, Emotet exploits “hijacked email threads and then [uses] those accounts as a launch point to trick victims into enabling macros of attached malicious office documents.” Additionally, researchers have observed the malware adjusting its tactics and techniques, which WaterISAC reported at the end of April. The threat actors have switched from non-secure HTTP to secured HTTPS communications, and they’ve also added in code obfuscation techniques to the payload. Also, almost 20 percent of all malicious emails observed exploited the 2017 Microsoft vulnerability CVE-2017-11882. After being infected with Emotet, threat actors can use the infected device to further propagate Emotet or load other third-party malware such as ransomware. Since Emotet spreads primarily via email, one of the best prevention methods is to refrain from opening suspicious emails. Read more at Darkreading.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar