An international law enforcement operation led by Europol and partner agencies seized control of the Emotet malware infrastructure, disrupting one of the world’s most dangerous botnets and cutting off a major delivery platform used to distribute additional malware. Investigators took over servers in multiple countries and redirected infected machines to law-enforcement-controlled infrastructure, undermining the criminal operation behind Emotet and preventing the botnet from continuing normal command-and-control activity.
After the takedown, authorities used that access to push a cleanup routine to infected devices, with reports indicating the uninstall action was scheduled for April 25, 2021 and ultimately reached about 1.6 million compromised systems. The removal mechanism was designed to delete Emotet from Windows hosts without installing unrelated software, marking an unusually direct post-seizure remediation effort aimed at reducing residual infections after the botnet’s infrastructure had been dismantled.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Authorities executed the planned remediation step by sending a cleanup module to infected machines, targeting about 1.6 million compromised devices worldwide. The patch was designed to remove Emotet from victim systems after the botnet takeover.
Using compromised-address data obtained after the Emotet server seizure, Spamhaus began contacting domain owners, organizations, and email providers in mid-April 2021 to reset passwords and secure affected accounts. The group later said more than 60% of the 1.3 million accounts in its dataset had been re-secured after two months.
Following the takedown, investigators announced plans to push a law-enforcement-controlled uninstall routine to infected systems. The cleanup action was set to automatically remove Emotet malware from compromised devices on April 25, 2021.
Authorities from multiple countries, coordinated through Europol and Eurojust, disrupted Emotet by taking control of its infrastructure and arresting alleged operators in Ukraine. Investigators said they had taken over the malware's command-and-control network as part of the global action.
According to Intel 471, the coordinated U.S. and European law enforcement action to seize Emotet infrastructure occurred on January 26, 2021. The operation preceded the public announcement the following day and included action against infrastructure tied to alleged operators in Ukraine.
After gaining access to Emotet's command-and-control servers, law enforcement quietly monitored the botnet's operations for several months to map its infrastructure and identify those behind it. This surveillance phase preceded the public takedown.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
npu.gov.ua
Open sourceintel471.com
Open sourcetherecord.media
Open sourcecpomagazine.com
Open sourcekrebsonsecurity.com
Open sourceeuropol.europa.eu
Open sourceeuropol.europa.eu
Open sourcezdnet.com
Open sourcebka.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.