A mysterious vigilante is sabotaging one of the world’s most dangerous malware strains

(Image credit: Shutterstock / Sapann Design)

The vicious Emotet botnet has been torpedoed by an unnamed vigilante hacker, who is exploiting weaknesses in the botnet’s infrastructure to sabotage operations.

The saboteur, who is battling with Emotet operators for control, is replacing malware payloads with animated GIFs, rendering the botnet effectively impotent.

Reports from Cryptolaemus, a group of researchers dedicated to monitoring Emotet, suggest the vigilante is sabotaging roughly a quarter of malicious downloads associated with the botnet.

Emotet botnet

The Emotet botnet is said to be among the world’s most dangerous malware strains and was revived only last week after a five-month hiatus, although the relaunch has been marred by the ongoing hack.

The attack on Emotet operations began on July 21 after the individual responsible managed to take control of web shells used to control payloads - and has escalated significantly in the six days since.

At first, the mysterious hacker meddled with only a handful of the botnet’s payloads, replacing malware downloads with comedy GIFs of James Franco, Blink 182 and Hackerman. The intrusion has continued to scale, however, and the vigilante has now reduced the botnet’s potency significantly.

“Since [the Emotet administrator] was having technical difficulties today, the hashes are way down and we barely saw much of anything,” wrote Cryptolaemus researcher Joseph Roosen on July 23.

The Emotet operators are reportedly still unable to eject the intruder from their systems, but have become more adept at spotting tampering and fixing malware payloads.

Although the identity of the mysterious saboteur remains unknown, rumors suggest either a rival cybercriminal syndicate or white hat hacker is responsible.

Via ZDNet

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all