Cybercrime DB

Emotet Malware Network Disruption and Arrests

A takedown that worked for only ten months before the malware returned stronger.

Contributing Editor · · 7 min read
Cover illustration for “Emotet Malware Network Disruption and Arrests”
malware operators and developers · September 6, 2026 · 7 min read · 1,686 words

Emotet started as a banking trojan in 2014 and ended up as a full-blown crime-as-a-service platform, one that a coordinated raid across eight countries managed to knock offline in 2021, only to watch it walk back ten months later. That's the whole story in two sentences. The rest is just figuring out how something built to steal login credentials from banks turned into infrastructure that Ryuk and Conti rented on demand.

Emotet went by other names too. Security researchers called it Geodo or Feodo, and the group running it got tagged Mealybug, MUMMY SPIDER, or TA542, depending on which vendor's naming scheme you were reading. The pivot is what matters. Somewhere along the way, Emotet's operators stopped being just attackers and became landlords. They built a pre-infected network of computers and rented access to it. Ryuk used it. Conti used it too. The damage those ransomware crews caused downstream dwarfed anything Emotet's own crew did directly, which is the whole point of running a service business instead of committing the crime yourself.

How Emotet's technical design made it self-sustaining and hard to detect

The infection routine was almost boring in its simplicity: a phishing email, a Word document, a prompt asking the victim to enable macros. Click yes, and the machine is theirs. From there, Emotet moved sideways through a network like water finding cracks in a foundation, worm-style, meaning a single careless click in the accounting department could end with every machine in the building compromised.

Once inside, infected hosts became spam factories. A single infected host could send dozens of emails per minute; scale that across an active botnet and the daily output ran into the hundreds of thousands. That volume alone would be a nuisance; the disguise made it dangerous.

Emotet used a trick called hashbusting: every infected machine generated a different file hash, so antivirus tools looking for a known signature were chasing a moving target. Then there was thread hijacking, arguably the nastiest bit of social engineering in the whole design. The malware would spoof a reply inside a real, stolen email conversation, so the message looked like it came from someone the recipient already trusted, continuing a thread they actually remembered. Nobody double-checks an email that quotes their own words back at them.

Underneath all of it sat a three-part server architecture, nicknamed Epoch 1, Epoch 2, and Epoch 3. No single server was a single point of failure; take one down, and the others kept the lights on. Emotet also became a delivery van for other malware: IcedID, TrickBot, QakBot, UmbreCrypt, Cobalt Strike beacons. Every one of those design choices, the hash-shuffling, the hijacked threads, the split infrastructure, served one purpose: staying alive longer than whoever was hunting it.

The scale of damage Emotet caused before anyone stopped it

Check Point put Emotet's damages at roughly $2.5 billion at its peak. The U.S. Department of Justice described it more loosely as hundreds of millions of dollars in worldwide losses, which is a wide range, but even the low end of that estimate buys a lot of remediation work. By the time the 2021 takedown happened, Emotet had infected somewhere between 1.5 and 1.6 million computers globally. More than 45,000 of those sat inside the United States, according to the DOJ.

CISA estimated that local, state, tribal, and territorial governments were paying up to $1 million per incident just to clean up after an infection. Allentown, Pennsylvania, found that out the hard way in February 2018: Emotet got into city government machines and left the city with a million-dollar bill to fix it.

Emotet's victims spanned the entire U.S. economy: school districts, small businesses, large companies, nonprofits, and government agencies at every level. The official damage figures almost certainly understate the real cost, because Emotet was selling the keys to other criminals who then caused harm of their own on top of whatever it did directly. Access-as-a-service keeps the full cost perpetually off the meter.

How eight countries and two international bodies dismantled the botnet in a single coordinated action

January 2021 brought a coordinated joint effort between the Netherlands, Germany, the United States, the United Kingdom, France, and Ukraine, organized through Europol and Eurojust. Authorities reached out internationally to hosting providers that were unknowingly serving Emotet's compromised IP addresses. The UK's National Crime Agency put the final count at roughly 700 command-and-control servers taken offline, key infrastructure located in the Netherlands.

The clever part was the sinkholing, beyond the arrests that also happened. Investigators seized the servers, then swapped Emotet's own malware out for a law-enforcement-built file, and let the botnet's own scheduled update system push that file out to every infected machine automatically. Emotet's own plumbing became the delivery mechanism for its own shutdown. Europol called it "a unique and new approach to effectively disrupt the activities of the facilitators of cybercrime," which is a fairly dry way of describing what amounts to poetic justice with a software patch.

Germany's federal police, the BKA, ran a parallel cleanup operation that auto-disabled Emotet on infected German machines. Ukrainian authorities made arrests targeting people managing the network's infrastructure; the raid footage showed seized computers alongside other assets, evidence of a clearly lucrative criminal enterprise.

Dutch police recovered a database of 600,000 stolen email addresses, usernames, and passwords, giving the public a way to assess their exposure. At the time, the prevailing assessment was that rebuilding the botnet would require starting from scratch. That confidence would age about as well as a New Year's resolution made on January 2nd.

Why the takedown held for only ten months

Diagram: Emotet's Rise, Fall, and Return: A Timeline. Visualizes: Show Emotet's key milestones as a horizontal timeline with six anchored events: 2014 (launched as banking trojan), 2018 (Allentown PA hit with $1M cleanup bill), January 2021…

Emotet came back in November 2021. Ten months, give or take. Rather than rebuilding from nothing as the FBI's statement implied, it re-emerged by leveraging existing criminal infrastructure to push a new version of Emotet back out to compromised machines. The old system was gone. A new one, wearing the same name, showed up wearing better armor: the cryptography was hardened, the control flows got tighter, and the infection methods changed shape.

The numbers made the comeback obvious fast. Deep Instinct clocked a 2,700% spike in detections in Q1 2022 compared to the quarter before, and new campaigns leaned on Microsoft Excel macros almost 900% more than they had previously. By late 2022, Emotet was pushing out hundreds of thousands of emails a day again, matching its pre-takedown volume. Conti and other ransomware affiliates started using Emotet's access to deploy their own payloads, which means the rental market for stolen infrastructure had quietly reopened for business.

The geography shifted too. In the 2022–2023 campaigns, Asia and Europe were among the most heavily targeted regions. Different map, same landlord.

Here's the uncomfortable part: the rebuild worked because the people survived alongside whatever servers did. Not every operator got arrested. The relationships with ransomware affiliates stayed intact. A malware-as-a-service model doesn't need its old servers back; it needs the knowledge of how to run the business and the customers who already know your name. The FBI's "rebuild from scratch" line described the hardware accurately and ignored the business entirely.

What Operation Endgame in 2024 attempted to do differently

By May 2024, law enforcement had clearly learned something from round one. Operation Endgame, coordinated again through Europol and Eurojust, went after multiple dropper malware families at once, including IcedID, Pikabot, Smokeloader, Bumblebee, SystemBC, and TrickBot. It was widely framed as a follow-up to the 2021 Emotet action, but with a wider net; the target was the layer of criminal services sitting underneath several pieces of infrastructure, rather than a single one of them.

The operation combined arrests, freezing of illegal proceeds, and botnet takedowns, a noticeably broader toolkit than simply unplugging servers. Investigators also named a person of interest, an individual going by "Odd," with aliases including Aron, C700, Cbd748, Ivanov Odd, Mors, Morse, and Veron, identified as the alleged mastermind behind Emotet and sought as part of the Endgame effort.

The logic here is straightforward. A botnet that can come back to life by borrowing someone else's infrastructure calls for taking down the whole neighborhood at once, address by address simultaneously. Whether that approach holds longer than the 2021 effort is still an open question. Emotet's activity trailed off as pressure mounted, though this isn't the first quiet stretch in Emotet's history, and previous silences have all ended the same way.

What the Emotet story tells practitioners about the limits of infrastructure disruption

Emotet's arc, trojan, service platform, resurrected service platform, makes one thing pretty clear: how resilient a criminal operation is depends on its business model above all else. A malware-as-a-service setup spreads the risk around. Seize the infrastructure, and the customer list survives, the tradecraft survives, and the market finds a new supplier. When Emotet went dark in 2021, BazarLoader and IcedID picked up some of the slack. Demand found a new vendor.

Thread hijacking and hashbusting point at a bigger lesson too: the malware that lasts is built with evasion baked into the blueprint from the start. And the quiet periods matter as much as the noisy ones. Emotet's operators go dark between campaigns on purpose, because defenders relax their guard the moment the alerts stop coming in. A pause is usually reloading.

The 2021 sinkholing operation deserves credit; turning a botnet's own update mechanism against itself was a genuinely new move, and it worked exactly as designed. Infrastructure was always the disposable part of the equation. Operation Endgame's shift toward hitting the whole dropper ecosystem at once is the obvious next step in the argument, but the criminal labor market underneath it, and the ransomware affiliates who keep funding it, are still standing.

For anyone tracking this class of threat, the practical takeaway is uncomfortable but simple: indicators of compromise from 2021 were dead weight by 2022. Emotet had already rebuilt its cryptography, changed its infection methods, and shifted its target geography. Signature-based detection chases yesterday's malware. Threat intelligence that follows actor behavior, who's renting access to whom, which affiliate groups keep showing up together, ages far better than a list of file hashes that expire the moment the botnet updates itself.

Sources

  1. justice.gov
  2. welivesecurity.com
  3. checkpoint.com
  4. fbi.gov
  5. europol.europa.eu

More in malware operators and developers