Emotet botnet infrastructure returning after the 2021 disruption

Emotet Malware Botnet Is Back

Emotet returned in November 2021, almost ten months after an international law-enforcement operation disrupted its command-and-control infrastructure. Researchers observed TrickBot installing a new Emotet build on previously compromised systems, giving the operators an initial foothold from which to rebuild the botnet.

EDIT: 6 July 2023: ESET researchers reported that Emotet ran three short campaigns in March 2023 while testing new delivery methods. These included OneNote files containing embedded VBScript after Microsoft began blocking macros from internet-sourced Office documents by default. ESET’s telemetry showed smaller campaigns and frequent changes in approach, suggesting that the operators were struggling to replace their former attack path.

EDIT: 01 May 2024: Feodo Tracker now reports that its current datasets are empty and that it is not tracking active command-and-control servers for the covered malware families. Its historical Emotet list shows the latest newly observed Emotet servers from March 2023 as offline. This is a current monitoring snapshot, not proof that Emotet, or its operators, can never return.

What happened in November 2021?

On 27 January 2021, investigators from several countries took control of hundreds of servers used by Emotet. Europol described the coordinated operation as a disruption of one of the most significant botnets of the previous decade.

  • Emotet had spread through large waves of malicious email, including messages inserted into stolen email conversations.
  • An infected system could receive additional payloads, turning Emotet into an initial-access service for other criminal groups.
  • On 15 November 2021, several research teams identified infrastructure and malware samples indicating that Emotet had returned.

During the early rebuilding phase, TrickBot reversed the relationship previously seen between the two malware families: instead of Emotet delivering TrickBot, systems already infected with TrickBot received the new Emotet build. At that stage, researchers did not yet see a large independent Emotet spam campaign.

Historical chart of Emotet botnet activity around its November 2021 return

Trackers subsequently observed new command-and-control servers appearing as the operators rebuilt their network. The return was therefore real, but its scale and resilience were still uncertain when this article was first published.

Historical list of Emotet command-and-control servers from November 2021

Why Emotet matters

Emotet began as a banking trojan but evolved into a modular loader and botnet. Its value to other criminals came from the access it provided: compromised systems could be used to steal email content, spread inside a network and install additional malware. That made an Emotet infection an entry point for wider compromise rather than an isolated endpoint alert.

What defenders should do

  • Keep Office’s protection against macros from the internet enabled, and use supported OneNote versions that block dangerous embedded file types.
  • Treat unexpected attachments and links as suspicious even when a message appears inside a genuine email conversation.
  • Keep email filtering, endpoint protection and Microsoft Office fully updated, and investigate any endpoint that attempts to contact known botnet infrastructure.
  • Use a current intelligence feed such as the Feodo Tracker blocklist. Do not permanently block old historical addresses without validation because IP addresses are reused and static lists can create false positives.

CISA’s Emotet advisory provides additional detection and mitigation guidance. A clean live feed is encouraging, but layered email, endpoint, identity and network controls remain necessary because delivery techniques and malware families change.

Sources


Originally published in November 2021. Updated in May 2024.

Leave a Reply

Your email address will not be published. Required fields are marked *