Law enforcement agencies from eight countries, coordinated by Europol and Eurojust, took control of the infrastructure behind Emotet. Europol described Emotet as one of the most significant botnets of the past decade.
What happened
- Authorities from the Netherlands, Germany, the US, the UK, France, Lithuania, Canada, and Ukraine took part.
- Emotet spread mainly through malicious email attachments and was rented to other criminals to deliver malware such as TrickBot and ransomware.
- Investigators took over its servers and redirected infected machines to law enforcement infrastructure.
- Emotet re-emerged in November 2021, rebuilt by its operators with help from other criminal groups.
Why it mattered
The takedown disrupted a major route for ransomware into organisations, though Emotet’s return showed the limits of infrastructure seizures without arrests of core operators. Police also used their access to push an update that removed the malware from infected computers in April 2021.
Lessons for organisations
Block or quarantine risky email attachments such as macro-enabled documents, keep endpoint protection updated, and treat any malware infection as a potential precursor to ransomware. Make sure staff can report suspicious emails easily and receive quick feedback.
Source: BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.