Home » today » Business » Emotet fell. The scepter was taken over by the Trojan horse Trickbot

Emotet fell. The scepter was taken over by the Trojan horse Trickbot

“Emotet is one of the most destructive variants of malware, so taking control of its infrastructure is a great success,” said Peter Kovalčík, Check Point’s security expert. At the same time, however, he emphasized that in January, Emotet was still the most widespread threat detected worldwide.

Emotet was originally a banking trojan, but over time it has developed into a destructive botnet. It has long been the most successful and widespread malware of 2020.

The first version of Emotet appeared in 2014. And since then, cybercriminals have been constantly improving this uninvited visitor, so that he has gradually always returned to the top of the list of the most widespread cyber threats. But even that is no longer possible after the botnet is taken out of service.

Trickbot took over the imaginary scepter among the most widespread threats last month. This uninvited visitor was spread by computer pirates mainly through a spam campaign, when they sent a fake Excel file. Once opened, Trickbot downloads to the victim’s computer, spreads it across the network, collects banking information, and tries to steal tax documents that could be further misused.

Trickbot was the fourth most widespread malware in 2020, affecting 8% of organizations worldwide. He played a key role in one of the most significant and costly cyber attacks in 2020, hitting Universal Health Services (UHS), a leading healthcare provider in the United States.

UHS was the victim of a Ryuk ransomware attack in which computer systems were blocked by the extortion virus. The lost profits and costs of the attack climbed to $ 67 million. It was Trickbot that was used to steal data from UHS systems and also to subsequently infect the system with ransomware.

“Criminals will continue to use existing threats and tools, and Trickbot is popular for its versatility. In addition, it has proven itself in previous attacks. As we expected, even if one major threat has been removed, this does not mean that organizations should slow down in their protection, because other dangerous threats are waiting for their chance, “added Petr Kadrmas, Security Engineering Eastern Europe at Check Point.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.