Emotet botnet malware taken down by global police sting

By William Smith
Emotet was first discovered as a banking Trojan in 2014, and allowed cybercriminals to gain unauthorised access to computer systems across the globe...

A botnet dubbed the “world’s most dangerous” has been disrupted by global police action, Europol has announced.

A botnet is created when malware overtakes a number of devices, linking the infected instances together. The size can grow exponentially as infected devices are added to the network and its computing power increases.

A long-standing threat

Emotet was first discovered as a banking Trojan (a malware that relies on misleading users into installing it) in 2014, and allowed cybercriminals to gain unauthorised access to computer systems across the globe. Attackers would then sell access to other criminal groups for purposes such as data theft or extortion.

A press release from Europol advised vigilance, saying: “cybersecurity awareness is essential to avoid falling victim to sophisticated botnets like EMOTET. Users should carefully check their email and avoid opening messages and especially attachments from unknown senders. If a message seems too good to be true, it likely is and emails that implore a sense of urgency should be avoided at all costs.”

Part of the danger of Emotet was its method of spreading - via infected word document email attachments. A prompt would be sent once the file was opened, at which point the malware could be installed on a computer.

Collaboration leads to success

Defeating the botnet required collaboration from police authorities in the Netherlands, Germany, the United States, the United Kingdom, France, Lithuania, Canada and Ukraine. Authorities gained control of the infrastructure, allowing them to take EMOTET down from the inside. Further, a database of compromised email addresses, usernames and passwords was released and published.

Commenting, Kimberly Goody, Senior Manager of Cybercrime Analysis, Mandiant Threat Intelligence, said: “Emotet has consistently remained one of the most widely distributed malware families in recent years. Between October 2020 and January 2021, we observed Emotet distribute multiple malware variants that have been used to enable ransomware operations, so it is plausible that this Emotet disruption may reduce the immediate victim pool for ransomware deployment in the short term.“

Share

Featured Articles

How Red Bull & Oracle are already winning with data

Amr Elrawi, Director, Sports Marketing and Business Development, Oracle, joined TECH LIVE LONDON to discuss how data built success with Red Bull Racing

Exec Q&A: Alex Cruz-Farmer, Cisco ThousandEyes

Alex Cruz-Farmer, Principal Product Manager at Cisco ThousandEyes, explains how their technology brings new levels of visibility to hidden DX issues.

Cloud & 5G - Day 2 highlights from the in-person stage

TECH LIVE LONDON returned to the Tobacco Dock last week. Stage host and Technology Magazine Editor in Chief, Alex Tuck, breaks down the presentations

Cloud & 5G - Day 1 highlights from the in-person stage

Cloud & Cybersecurity

TECH LIVE LONDON: Day 2 highlights of the hybrid tech show

Digital Transformation

TECH LIVE LONDON: An overview of the hybrid technology show

Digital Transformation