Emotet Campaign Abuses Stolen PAC Emails to Targets Political Groups
A new phishing wave tied to the resurgence of Emotet is using stolen content from legitimate political action committee (PAC) mailers to trick victims. The campaign, first observed by Area 1 Security on August 21, exploits public interest in President Trump's decision to halt U.S. funding for the World Health Organization (WHO). The emails impersonate a typical PAC outreach message supporting the president's reelection, but the real payload is the Emotet banking trojan.

The phishing message is prefaced with "Fwd:Breaking: President. Trump suspends funding to WHO" and relies on display name spoofing to hide the actual sender. All sender accounts observed in the campaign are legitimate email addresses that were compromised by the attackers. The body of the email contains fully functional links to benign pages of the impersonated PAC, lending authenticity to the ruse.
Compromised Infrastructure and Authentication Abuse
The campaign uses compromised hosts both for sending and as part of the malware delivery chain. One sending Mail Transfer Agent (MTA), server[.]websoftperu[.]com, is suspected to have been breached via an outdated OpenSSH 7.4 installation with known vulnerabilities. Other compromised accounts belonging to small businesses worldwide were used across multiple waves of the campaign, each time with the same stolen PAC content.
Beyond the WHO-themed lure, the same accounts were observed sending other politically-themed messages containing content stolen from additional PAC mailers, with the goal of infecting politically-affiliated targets with Emotet.
The attackers rely on compromised accounts to pass email authentication checks such as SPF, DKIM, and DMARC. Rather than targeting domains that lack these protocols, this actor deliberately exploits properly configured authentication to bypass security tools that treat passing authentication as a sign of legitimacy.
Roughly one week passes between campaign waves, during which the attacker rotates the weaponized attachment and swaps in fresh compromised sender infrastructure. This cadence helps evade signature-based defenses that depend on known IP addresses and payload hashes.
Malware Delivery and Execution
The email contains a Microsoft Word document with VBA macros that serve as the first-stage payload. When opened, a prompt asks the user to enable editing and content.

Enabling content triggers a heavily obfuscated VBA macro that runs an equally obfuscated PowerShell command via Windows Management Instrumentation (WMI).

After deobfuscation, the PowerShell script is seen attempting to download Emotet from a hardcoded list of compromised WordPress sites. The script checks each site in the list to determine which ones are still actively hosting the trojan.

At the time of analysis, only one URL in the list — hxxp://cammis[.]com[.]br/wp-admin/8IArx/ — was still serving the payload. The downloaded executable is stored in the %userprofiles%\AppData\Local\ directory, after which the malware sends a confirmation message to the Emotet command-and-control server.
Detection Challenges
Emotet's modular architecture and polymorphic DLLs allow it to continuously change its signature, frustrating hash-based detection. The malware is also aware of virtual environments and can sleep indefinitely to thwart debugging attempts. Once a device is infected, Emotet's worm-like self-propagation puts other hosts on the network at risk, and sensitive data on compromised machines is effectively exposed.
Attackers behind this campaign also vary the file name and hash of the malicious attachment between waves, further reducing the chance that legacy email gateways will flag the messages.
Indicators of Compromise
Compromised Sender Email Addresses:
- accounts@alhilaldecors[.]com
- reservas@carentminibus[.]com
- sargodha@deluxefootwear[.]com[.]pk
- c25@hahncollections[.]co[.]za
Sender IP Addresses:
- 59[.]127[.]189[.]26
- 103[.]133[.]214[.]57
- 175[.]138[.]0[.]109
- 208[.]109[.]80[.]1
Sender Domains:
- Server1[.]gigafield[.]com
- Server[.]websoftperu[.]com
Compromised Emotet Websites:
- hxxp://cammis[.]com[.]br/wp-admin/8lArx/
- hxxps://indiafricatoday[.]com/wp-admin/l0WmSB/
- hxxp://gosmartmoving[.]com/wp-content/3QC/
- hxxp://ilfacomercial[.]cl/wp-includes/P/
- hxxp://hanh[.]cz/blogs/XU/
- hxxps://myvanillastuffs[.]xyz/wp-admin/hjL8d/
- hxxp://condi-shop[.]ru/wp-includes/nWJ/
Attachment Hashes:
- MD5: 031be6a39da92ccedefc3ef3e5cc12aa — SHA1: 1eed6a05b977b6b13a8df2cafed8f1cdf7d53088 — SHA256: 5d4bee6f5bb0d02b980f21c2ae731bd12d5de2e2810058e6098fc888a7cc6f7b
- MD5: 729d528ab5073b012c6dcded3872bb62 — SHA1: 1984ee2ffcfc14beec272f671833bf506ab85f72 — SHA256: d647fbb82b18f11ade1b505a7f9a065441fe8a187377299900bae27fe4047740
- MD5: 86b7f3f18a2e57ae66ba824b0c43be01 — SHA1: ea1302e16d433653adf3071325bc8c2288b2a85e — SHA256: 874b498a569260ed044256f13bd87d1a3697f02a17a364d2d61ba9005e12cd25
- MD5: 7dc4f1c537c0557a3e38106803b43449 — SHA1: acd368c99c7071461701bec70dcd113ad028fbbb — SHA256: 08c3d787f8a45044c85e4c95fb935cbab569d48a16dbe511b8abf6b79fa08046
Attachment File Names:
- Report.doc
- Resume.doc
- LG-7231 Medical report Covid-19.doc
- IQ-5125 Medical report Covid-19.doc
PowerShell Executables (file names are seven alphanumeric characters):
- Qncqa3a.exe
- S1xi8fyw.exe



