Millions of email addresses harvested by the Emotet botnet for malware distribution campaigns have been released by the FBIas part of the agency's effort to "clean up" infected computers. Users and domain owners can now find out if Emotet has affected their accountsby searching the database of email addresses stolen by Emotet.
Earlier this year, law enforcement and judicial authorities from around the world conducted a joint operation, dubbed “Operation Ladybird,” that took down the Emotet botnet. Now, researchers have taken control of its infrastructure, following an international coordinated effort. On April 25, law enforcement released an update that removed the Emotet malware from all affected systems.
Read also: Emotet malware removed from all infected computers!

This operation was the result of a joint effort between authorities from the Netherlands, Germany, the USA, the UK, France, Lithuania, Canada and Ukraine, with the international activity coordinated by Europol and Eurojust.
In addition to computer systems, Emotet also compromised a large number of email addresses and used them for its “business.” The FBI now wants to provide the owners of these email addresses with a quick way to check if they have been affected by Emotet.
Thus, the FBI and the Dutch National High-Tech Crime Unit (NHTCU) shared 4,324,770 email addresses stolen by Emotet with the data breach notification service “Have I Been Pwned (HIBP)”.
See also: Emotet: The botnet was "destroyed" by an international police operation!
Troy Hunt, the creator of HIBP, said that 39% of these email addresses had already been indexed as part of other data breach incidents. The email addresses belong to users from numerous countries. They came from links stored in Emotet's infrastructure for sending malicious emails or were collected from users' web browsers.

Given its sensitive nature, Emotet data is not publicly searchable. Subscribers to the service affected by the Emotet breach have already been notified, Troy Hunt said. Additionally, referring to the verification process, Hunt noted that individuals will need to either verify address control through the notification service, or perform a domain lookup to see if they are affected.
The Dutch National Police, which was part of the operation to take down Emotet, has a similar search service where users can check if Emotet compromised their emails.
Proposal: DHS: SolarWinds hackers breached officials' email accounts

Users can enter an email address and if their account is part of the data collected by the Emotet botnet, Dutch police will send them a message with instructions on what to do. On February 3, Dutch police added 3.6 million email addresses to their monitoring service.
Another service, called “Have I Been Emotet” by cybersecurity firm TG Soft, was released on October 1, 2020.It checks whether Emotet used an email address as a sender or recipient. However, it was last updated on January 25, two days before the botnet was taken down.

Emotet is one of the most notorious botnets of this decade, having caused hundreds of millions of dollars in damage, while infecting over 1.5 million computers in about nine months.
Furthermore, it played a significant role in the distribution chain of many ransomware strains, as it often distributed the QakBot and Trickbot on a compromised network, which in turn distributed ProLock or Egregor, and Ryuk and Conti, respectively.
On January 27, all three Epochs – subgroups of the Emotet botnet with separate infrastructure – were brought under the control of law enforcement agencies.
