HomeSecurityEmotet malware removed from all infected computers!

Emotet malware removed from all infected computers!

Emotet, one of the most dangerous email spam botnets recently recorded, was uninstalled from all infected devices on April 25 , with the help of a malware module delivered by law enforcement in January. The botnet’s takedown is the result of an international law enforcement operation that allowed researchers to take control of Emotet’s servers and shut down the malware.

Emotet was used by the hacking group “TA542” (also known as Mummy Spider) to deploy second-stage malware payloads, including QBot and Trickbot, on victims’ computers. TA542’s attacks typically resulted in a complete network compromise and the deployment of ransomware payloads on all infected systems, including ProLock or Egregor from Qbot, and Ryuk and Conti from TrickBot.

Read also: Microsoft: "Don't relax your defenses. Emotet may return"

Emotet malware
Emotet malware removed from all infected computers!

How the Emotet uninstaller works After the botnet takedown operation, the police pushed a new configuration to “active infections” of Emotet, so that the malware began using C2 servers controlled by the Bundeskriminalamt , the German Federal Police . The police then distributed a new Emotet module in the form of the 32-bit EmotetLoader.dll to all infected systems, which automatically uninstalled the malware on April 25. Malwarebytes security researchers Jérôme Segura and Hasherezade took a close look at the uninstaller module.

After they changed the system clock on a test machine to activate the module, they found that it only deletes the relevant Windows services, autorun Registry keys and, subsequently, terminates the process, leaving «untouched» the rest on the compromised devices.

See also: QBot trojan replaces IcedID in malspam campaigns!

Emotet malware
Emotet malware removed from all infected computers!

In January, when the Emotet botnet was taken down in an international police operation, Europol told BleepingComputer that the German Federal Police Bundeskriminalamt (BKA) was responsible for creating and promoting the uninstall module. In a press release on January 28, the US Department of Justice (DoJ) also confirmed that the Bundeskriminalamt promoted the uninstall module to computers infected with Emotet.

Specifically, the DoJ stated the following: “Foreign law enforcement agencies, in cooperation with the FBI, replaced the Emotet malware on servers under their jurisdiction with a file created by law enforcement. The law enforcement file does not remove other malware that has already been installed on an infected computer via Emotet. Rather, it is designed to prevent the installation of additional malware on the infected computer by disconnecting the victim’s computer from the botnet.”

malware
Emotet malware removed from all infected computers!

Suggestion: Prometei botnet targets unpatched Microsoft Exchange servers!

The Bundeskriminalamt told BleepingComputer in January that the removal of Emotet was delayed because more evidence needed to be collected to remove the malware from infected devices. However, the Bundeskriminalamt explained that it could not provide further information as the investigation is ongoing.

Earlier this month, the FBI coordinated a court‑approved operation to remove web shells from Microsoft Exchange servers in the United States, which had been compromised by exploiting the “ProxyLogon” vulnerabilities, without first notifying the server owners. The FBI said it removed only the web shells and did not apply security updates nor remove other malware that hackers may have deployed on the servers.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS