What's the point of breaking up Emotet?

Fireeye News

Share post

“Emotet has always been one of the most widespread malware families in recent years. What are the long-term benefits of breaking up Emotet? A comment from FireEye.

While it has historically been linked to home banking fraud, the malware has also been used to spread spam and secondary malware since 2017. We believe this was done on behalf of a limited number of groups using Emotet as malware-as-a-service.

Ransomware campaigns with Emotet

Between October 2020 and January 2021, we observed that Emotet was spreading several variants of malware. These were used to enable ransomware campaigns. Thus, it seems plausible that breaking up Emotet could reduce the immediate victims of ransomware attacks in the short term. However, Mandiant has observed in the past how hacking groups rebuild their botnets after other takedown or smashing actions. The likelihood of this scenario depends on the status of the arrested people.

Helpful actors: Trickbot, Qakbot and Silentnight

The actors behind Emotet sometimes cooperate with other well-known malware campaigns, including Trickbot, Qakbot and Silentnight. In addition to the spread of these malware families as secondary malware by Emotet, we have occasionally observed in the past that these malware families also spread Emotet in reverse. These existing partnerships and re-spamming could be used to rebuild the botnet. ”- Kimberly Goody, Senior Manager of Cybercrime Analysis, Mandiant Threat Intelligence at FireEye

More at Barracuda.com

 


About Trellix

Trellix is ​​a global company redefining the future of cybersecurity. The company's open and native Extended Detection and Response (XDR) platform helps organizations facing today's most advanced threats gain confidence that their operations are protected and resilient. Trellix security experts, along with an extensive partner ecosystem, accelerate technology innovation through machine learning and automation to support over 40.000 business and government customers.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more