Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs
- Reference: 1619415189
- News link: https://www.theregister.co.uk/2021/04/26/emotet_sunday_25_april_killswitch_date/
- Source link:
This specially crafted time bomb caused the software to self-destruct on Sunday, April 25. The code was distributed at the end of January to Emotet-infected computers by the malware's command-and-control (C2) infrastructure, which had just been [1]seized in a multinational police operation.
[2]
Those [3]raids were largely successful: on Friday this week, malware tracker site Abuse.ch’s [4]Emotet portal showed none of the Emotet C2 servers it tracks were online.
As the dust settled from the swoops, the officers and agents involved wondered what to do next. The answer was to set a firm death date. Infosec bods [5]subsequently spotted that the backend systems seized by the police had made available a software update for Emotet that, once automatically downloaded and quietly installed, would activate an uninstall routine this weekend.
Infosec outfit MalwareBytes [6]confirmed on Sunday that its updated Emotet install had indeed completely removed itself as expected.
[7]
Mariya Grozdanova, a threat intelligence analyst at Redscan, described the cops' deinstallation code to The Register : “The EmotetLoader.dll is a 32-bit DLL responsible for removing the malware from all infected computers. This will ensure that all services related to Emotet will be deleted, the run key in the Windows registry is removed – so that no more Emotet modules are started automatically – and all running Emotet processes are terminated.”
[8]Game over, LAN, game over! Windows software nasty Emotet spotted spreading via brute-forced Wi-Fi networks
[9]Insult to injury: Malware menace soaks water-logged utility ravaged by Hurricane Florence
[10]Alaskan borough dusts off the typewriters after ransomware crims pwn entire network
[11]You have to be very on-trend as a cybercrook – hence why coronavirus-themed phishing is this year's must-have look
The move has similarities to the FBI's cleaning-up of infected Microsoft Exchange Server deployments this month, a move that prompted considerable debate when we revealed [12]the same thing could be lawfully done in the UK.
Emotet was particularly nasty in that it spread via malicious attachments in spam emails, and once installed, could bring in additional malware: infected machines were rented out to crooks to install things like ransomware and code that drained victims' online bank accounts. Computer security biz Digital Shadows [13]highlighted the extent of the Emotet epidemic, and said its removal is an overall win for everyone:
Prior to law enforcement’s takedown of Emotet, the malware reportedly controlled over one million machines. Emotet is also estimated to have made an almighty haul of over $2 billion over the years. Given the exceptionally large financial losses, the seizure of Emotet was almost certainly deemed to be a necessary objective of law enforcement. In this sense, its importance is clear to see. Emotet has dominated the cyber threat landscape, and taking it off the board represents a symbolic and strategic victory.
Before the weekend, Redscan’s Grozdanova told The Register Dutch authorities distributed the DLL, adding "there might be German involvement as well since the international team that disrupted Emotet was led by both Dutch and German investigators."
It’s entirely probable that some Emotet-infected devices were located in the UK. Technically speaking, the Europeans may have committed [14]criminal offences under Blighty's Computer Misuse Act due to the way they chose to remove the malware without the permission of the PCs’ owners. Not that any prosecutor would ever pursue those claims, though the point remains.
[15]
Interestingly enough, the US Dept of Justice, which also played a role in the seizure of the malware's servers, said in a [16]statement in January that "foreign law enforcement, working in collaboration with the FBI, replaced Emotet malware on servers located in their jurisdiction with a file created by law enforcement," a file that prevented Emotet's masterminds from ever regaining control of infected PCs. The Feds did not mention anything about a delayed uninstall routine, and stressed any changes to systems were done by foreigners.
Neither the Germans nor the Dutch have gone on the record as owning Sunday’s execution of Emotet. In late January, [17]Germany and [18]the Netherlands said they had, via Emotet control servers seized in their jurisdictions, released a software update that quarantined Emotet infections on people's PCs, and directed connections from the malware to evidence-gathering systems, thus ensuring the software nasty's perpetrators could no longer send commands to their botnet.
Paul Robichaux, senior director of product management at IT forensics firm Quest, told us: “These kind of large-scale, coordinated attacks and global botnets are too big for individual organisations to resolve entirely themselves, and leaving individual companies to clean them up themselves is a legitimate national security problem. However, the fact that law enforcement is on the case is no excuse to let your guard down. You still need to focus on securing your own environments.” ®
Get our [19]Tech Resources
[1] https://www.theregister.com/2021/01/27/emotet_botnet_taken_down_europol/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIaPP0UcotajLkw7UPqh@wAAAIU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action
[4] https://feodotracker.abuse.ch/browse/emotet/
[5] https://blog.malwarebytes.com/threat-analysis/2021/01/cleaning-up-after-emotet-the-law-enforcement-file/
[6] https://twitter.com/MBThreatIntel/status/1386413655659479043
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIaPP0UcotajLkw7UPqh@wAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] http://www.theregister.com/2020/02/10/emotet_spreads_over_wifi/
[9] http://www.theregister.com/2018/10/16/ransomware_water_carolina/
[10] http://www.theregister.com/2018/08/03/alaskan_town_has_entire_network_owned_by_ransomware_crims/
[11] http://www.theregister.com/2020/09/17/f_secure_h1_2020_cybersecurity_report/
[12] https://www.theregister.com/2021/04/19/ncsc_exchange_server_legal_powers_question/
[13] https://www.digitalshadows.com/blog-and-research/the-emotet-shutdown-explained/
[14] https://www.legislation.gov.uk/ukpga/1990/18/section/1
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIaPP0UcotajLkw7UPqh@wAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://www.justice.gov/opa/pr/emotet-botnet-disrupted-international-cyber-operation
[17] https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2021/Presse2021/210127_pmEmotet.html
[18] https://www.politie.nl/nieuws/2021/januari/27/11-internationale-politieoperatie-ladybird-botnet-emotet-wereldwijd-ontmanteld.html
[19] https://whitepapers.theregister.com/
Re: Bad-Good
As I read the article, the uninstall used the compromised malware framework, so would only happen on systems that were already infected. If you've kept your PC protected & malware-free nothing would happen. This isn't a case of the white hats using an exploit to break into your system for some arguably-beneficial purpose, they are modifying malware you've already 'caught' to uninstall itself. I think that's less of a concern.
Re: Bad-Good
This is difficult.
On the one hand, they "owned" the software and simply pushed an update - that's done all the time. On the other hand they "took control" of the software and changed it's original function to modify users' machines. Admittedly in this case it was a piece of software used illegally but what if it was a piece of legit software that the authorities didn't like? Take as an example an encryption tool for a chat app because children, darkweb, criminals ... you know the usual buzzwords. On the one hand, that tool *could* be used for nefarious purposes but, on the other, it *is* used by the majority for totally legit private communication, to conduct secure company deals, to act as a private communications conduit for those (legitimately) opposed to the Government, to arrange interior decorating contracts or whatever. Would it then be ok for the powers that be to declare that they've taken ownership of that software and then kill the encryption on users' machines using a normal push update because of children, darkweb etc etc ...? A bit like taking all cars off the road because bank robbers use them.
I think we're dipping toes into some very deep water. The only limit seems to be the requirement for a warrant to perform such functions ... except in this European case where there is no mention at all of judicial oversight proceedures.
Food for thought
I've no quibble with this action, but am concerned it could be the thin edge of a very nasty wedge. What's the prospect of necessary slowly morphing into desirable and hence to total surveillance?
Tin foil hats
Why isn't there a vaccine against paranoia?
Dang it! The service I was offering to clean the Emotet malware for $$$ is now stymied. I'll have to sue the Government for ruining my business. It's not their job to do for free what business can charge for. It's communism I tell you!
In the UK we already have secret surveillance that can't be referred to in court when evidence is being produced. (Not the evidence that can't be referred to but the fact that it was obtained by secret methods with absolutely no proper scrutiny or challenge.) So worries about state interference might seem justified, but in this case some clever so-and-so had the bright idea for getting the malware to uninstall itself. Remember that the state-actors already had control of the command infrastructure, so they could have used that for naughty purposes. Which would you rather have. Well done whoever thought of this for a neat hack.
Re: Tin foil hats
I'll go one step further... is my real day job in jeopardy, not just a side hustle removing malware? I'd just like some notice, so I can start a pottery business...
Bad-Good
Not sure on this, on the one hand they’ve stopped a nasty, on the other to my mind installing stuff on people’s computers without permission is a no no.
What if something breaks and they are to blame?
What if the nasty was keeping other nasties away?
Governments clandestinely being system admins to machines around the globe is an issue.
Microsoft need to put something in their eula that makes these activities legit.