Skip to content

Malware

Emmenhtal

aka IDATDropper · PEAKLIGHT

Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024.

Emmenhtal, also known as IDATDropper, PEAKLIGHT, is a Windows malware family.

Background

Emmenhtal is a malicious loader thought to have been in circulation since the start of 2024, with the first public analysis published by Orange Cyberdefense CERT in August 2024. The loader uses an obfuscated, multi-stage chain: it abuses the mshta.exe LOLBIN to read an initial HTA stage carrying embedded JavaScript, which once executed decodes and runs a PowerShell script. That script in turn decrypts an obfuscated PowerShell loader that ultimately pulls down and launches final-stage stealers and commodity RATs. By March 2025, Orange Cyberdefense CERT had observed three distinct versions of the loader, all in active distribution.


Source: Malpedia (Fraunhofer FKIE).