Authorities Plan To Mass-Uninstall Emotet From Infected Hosts on March 25 (zdnet.com) 26
Law enforcement officials in the Netherlands are in the process of delivering an Emotet update that will remove the malware from all infected computers on March 25, 2021, ZDNet has learned today. From a report: The update was made possible after law enforcement agencies from across eight countries orchestrated a coordinated takedown this week to seize servers and arrest individuals behind Emotet, considered today's largest malware botnet. While servers were located across multiple countries, Dutch officials said that two of three of Emotet's primary command and control (C&C) servers were located inside its borders. Dutch police officials said today they used their access to these two crucial servers to deploy a boobytrapped Emotet update to all infected hosts. According to public reports, also confirmed by ZDNet with two cyber-security firms that have historically tracked Emotet operations, this update contains a time-bomb-like code that will uninstall the Emotet malware on March 25, 2021, at 12:00, the local time of each computer.
Why wait until March? (Score:4, Insightful)
two months to exploit the botnet for their own purposes?
Re:Why wait until March? (Score:5, Informative)
That was my question as well. TFA gives the reason for the delay:
"Pargman is now urging companies to take advantage of this time window until March 25 to investigate internal networks for the presence of the Emotet malware and see if other gangs used it to deploy other threats.
After Emotet uninstalls itself on March 25, such investigations will be harder to carry out."
APRIL, not March (Score:3)
Apparently, according to MSDN time structure, "month" is a variable running from 0 to 11, so "3/25" means April 25.
Lets see how many things break... (Score:2)
Worst case is that they kill some really expensive industrial installations. Best case is no problems at all. Will be interesting to see.
Re: (Score:3)
Re: (Score:3)
now with C&C servers all seized,
Krebsonsecurity.com [krebsonsecurity.com] reports that according to Feodotracker, 20 out of 98 servers remain active.
Contact the owners? (Score:4, Insightful)
They should at least try to contact the owners of the infected machines. Too often the reason security isn't taken seriously is because managers believe that they haven't been hacked yet so why worry. They seem to be unaware that the world has changed since the nineties, most hackers today aren't skiddies doing it for the lulz but criminals or state actors who are trying to be invisible. Especially when security has been defunded to the point where it can't even detect threats let alone defend against them, these intrusions can easily remain invisible, leading to justifications for even more defunding. Contacting the owners might give management the heads up of how things really are.
Also, if they handle GDPR protected data, it should be made public that they got infected. People should know that their data may have leaked.
legal? (Score:4, Insightful)
Re: legal? (Score:3, Insightful)
Let's be honest and sane though They are removing malware from people's computers. They aren' doing any evil, nor do they intend to.
It is more like assistance for people so mentally disabled they need a legal guardian to survive.
Re: (Score:2)
Re: (Score:2)
It's like Covid. Your computer is infected. It can either get vaccinated or be forced into isolation (unplug your Internet connection).
EULA (Score:2)
Re: (Score:1)
M$ EULA is in fact illegal in most countries. By law most countries require that ALL conditions of sale be on clear display at the point of sale ie you sell a disc in a carboard box, then the EULA must be printed clearly on the box. Further to this all post purchase contract conditions are also illegal.
The USA and some third world countries are the only countries corrupt enough to allow the enforcement of post purchase agreements. It is a corrupt as it gets.
Re: (Score:2)
The code belongs to a criminal organization and is evidence of an ongoing crime. If you chose to claim ownership of an instance of this code that appears on your computer, that would mean either a) you are part of the criminal organization, or b) you stole it from the criminal organization. At least if you concede a) you get the Dutch equivalent of due process.
Re: (Score:2)
They are from The Government, and they are here to help.
More to the point... What are you going to do about it? Complain? To whom? And will they care?
But mah freedomz!! -- Muricans (Score:2)
"Demz gubberment regulations be teh devil!"
Or does that only apply to being abused by officially incorporated criminals?
I spoke too soon. (Score:2)
The comments here are full of literally exactly what I was saying as a joke here.
Seriously... if there ever was a lost cause of a society...
I was not able to find who are affected by Emotet. (Score:1)