The Death Of Emotet: Killing A $2 Billion Malware Campaign

Emotet, the notorious Microsoft Windows malware strain, is said to have a cybercrime operation believed to be from Ukraine.

First found in 2014 in the wild, the malware has been one of the most prevalent threats of all time. With servers found in many places around the world, Emotet had disrupted many companies and businesses.

The malware was best known as a banking trojan, crafted to steal banking credentials from infected devices.

To infect its victims, Emotet's main medium to spread, is through emails, appearing as if they are replies to earlier messages that were previously sent by the victims.

After further development, the malware was enhanced and became more like a loader, which allows its operators to infect victims with even more malware and more vicious payloads. Later on, Emotet is best known as a malware to create bot armies from infected computers, and also a MaaS (Malware-as-a-Service) with clients that include the Ryuk gang.

And this time, the authorities have put an end to this massive disruptive campaign.

Emotet

The Europol on its newsroom post, dubbed Emotet as the "world's most dangerous malware."

The attempt to kill Emotet first started early in 2020, when cybersecurity companies and the authorities detected various Emotet campaigns that infected victims with TrickBot and Qbot. It was then found that the authors of the Emotet malware used parked domains to distribute the payloads.

Then finally, it was in January 2021, that an international action coordinated by Europol and Eurojust allowed investigators to take control of and disrupt the Emotet infrastructure.

This was then followed by a number of arrests in Ukraine.

While the servers have been seized, Emotet has infected more than a million computers.

This was why the authorities created a specially-crafted "time bomb," and planted it to the malware's command-and-control (C2) infrastructure, to command them to self-destruct all instances of the malware in computers around the world.

And this time bomb detonated on April 25.

[block:block=87]

Authorities from Germany and the Netherlands have said that they had released a software update that quarantined infections on people's PCs, and directed connections from the malware to evidence-gathering systems, in order to ensure that the malware's perpetrators could no longer send commands to their botnet.

Using a file called the EmotetLoader.dll, the authorities use this 32-bit DLL to remove the malware from all infected computers. This ensures that all services related to Emotet are deleted, and the run key in the Windows registry is removed. This terminates all processes of Emotet present inside a Windows system.

"Germany initiates 'takedown' as part of internationally coordinated measures - malicious software on numerous victim systems is rendered unusable for the perpetrators," the German authorities said in a press release.

"With the removal of the servers behind the aggressive malware Emotet, an important battle has been made in the fight against cybercrime: the Emotet infection is no longer active on the computers of more than 1 million victims worldwide," said the Dutch authorities in an announcement.

Before the authorities took down this particular malware, the campaign is said to have caused an estimated damage of over $2 billion.

Given the exceptionally large financial losses, killing Emotet once and for all is certainly a necessary thing to ensure a safer internet.

Besides for the authors of the malware, the death of Emotet is a victory for everyone.

It is also reported that the U.S. Department of Justice had also taken part in this takedown, saying in its own press release that "foreign law enforcement, working in collaboration with the FBI, replaced Emotet malware on servers located in their jurisdiction with a file created by law enforcement."