Government release
Emotet Botnet Disrupted in International Cyber Operation
U.S. Department of Justice, Office of Public Affairs, January 28, 2021. The Emotet disruption's U.S. legal mechanism — an unsealed search warrant affidavit under which foreign law enforcement, working with the FBI, replaced Emotet malware on servers located abroad — and the U.S. participants and their roles: the U.S. Attorney's Office for the Middle District of North Carolina, the FBI Charlotte Division and the Criminal Division's CCIPS conducted the operation in cooperation with Europol and Eurojust and partners in Canada, France, Germany, Lithuania, the Netherlands, Sweden, Ukraine and the UK..
- Source type
- Government release
- Published
- January 28, 2021
- Research grade
- P1
- Used in entries
- 3
Bibliographic record
- Publisher
- U.S. Department of Justice, Office of Public Affairs
- Published
- January 28, 2021
- Source type
- Government release
- Research grade
- Source grade P1
- Language
- English
- Official record
- Official publication
- Address
- https://www.justice.gov/archives/opa/pr/emotet-botnet-disrupted-international-cyber-operation
- What it supports
- The Emotet disruption's U.S. legal mechanism — an unsealed search warrant affidavit under which foreign law enforcement, working with the FBI, replaced Emotet malware on servers located abroad — and the U.S. participants and their roles: the U.S. Attorney's Office for the Middle District of North Carolina, the FBI Charlotte Division and the Criminal Division's CCIPS conducted the operation in cooperation with Europol and Eurojust and partners in Canada, France, Germany, Lithuania, the Netherlands, Sweden, Ukraine and the UK.
- Dataset id
- src_usdoj_emotet_2021
Research notes
- The cited /opa/pr/ URL 301-redirects to the /archives/opa/pr/ path recorded here.
- Release date 2021-01-28, one day after the international action was announced in Europe.
How this source is used
Cited 3 times across 3 record types.
The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.
Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.
Cited by
Takedown records
1 citation
Cited on the takedown record itself.
-
Operation LadybirdSupporting source
Malware and botnets, January 2021
Organization roles
1 citation
Cited for an organization's recorded role in a takedown.
-
Federal Bureau of InvestigationPrimary source
Investigating, Operation Ladybird
Infrastructure
1 citation
Cited for infrastructure recorded as acted on.
-
Malware installationPrimary source
Malware installation remediated, Operation Ladybird