Don’t do SECURITY. Do business SECURELY.

International operation takes down Emotet botnet

Law enforcement from eight countries, coordinated by Europol and Eurojust, disrupts Emotet, one of the most widespread malware networks.

Law enforcement agencies from eight countries, coordinated by Europol and Eurojust, took control of the infrastructure behind Emotet. Europol described Emotet as one of the most significant botnets of the past decade.

What happened

  • Authorities from the Netherlands, Germany, the US, the UK, France, Lithuania, Canada, and Ukraine took part.
  • Emotet spread mainly through malicious email attachments and was rented to other criminals to deliver malware such as TrickBot and ransomware.
  • Investigators took over its servers and redirected infected machines to law enforcement infrastructure.
  • Emotet re-emerged in November 2021, rebuilt by its operators with help from other criminal groups.

Why it mattered

The takedown disrupted a major route for ransomware into organisations, though Emotet’s return showed the limits of infrastructure seizures without arrests of core operators. Police also used their access to push an update that removed the malware from infected computers in April 2021.

Lessons for organisations

Block or quarantine risky email attachments such as macro-enabled documents, keep endpoint protection updated, and treat any malware infection as a potential precursor to ransomware. Make sure staff can report suspicious emails easily and receive quick feedback.

Source: BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights