WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Emotet, Everybody’s Email Enemy (Re)Emerges and Could Lead to More Ransomware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Emotet, Everybody’s Email Enemy (Re)Emerges and Could Lead to More Ransomware

Author: Jennifer Walker

Created: Tuesday, November 16, 2021 - 19:19

Categories: Cybersecurity, Security Preparedness

There are few things that are absolute. Cyber threats being fully eradicated isn’t one of them. Despite the globally coordinated law enforcement action in January and follow up mass uninstall effort in April to expunge this formidable foe, Emotet has awoke. Teaming up with its’ old pal, Emotet has been observed using TrickBot’s existing infrastructure to rebuild – with over 264 infected devices already acting as command and control servers at the time of this writing. As Emotet regenerates, there hasn’t been any spamming activity observed yet. However, analysis reveals that Emotet has evolved. The current version is reported to employ 7 commands (versus its previous 3-4) and is expected to lead to a surge in ransomware infections. Prior to the takedown, Emotet was adept at deploying multiple ransomware families, including Ryuk, Conti, ProLock, Egregor, and many more. To proactively defend against Emotet, members are encouraged to track and block its command and control servers. Associated IP addresses can be found on a list maintained by the malware tracking group Abuse.ch. For more, including defense tactics, read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER) New IOCs (Stryker) and Malware Analysis Report (F5 BIG-IP)

Jun 5, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) EPA to Conduct 2026 National Cyber Drill Focused on Operating Without Telecommunications and Internet Connectivity

Jun 4, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) CISA and Partners Urge Hardening Automatic Tank Gauge Systems

Jun 4, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar