Malware · critical

How to fixEMOTET_BOTNET_LOADER

Emotet Banking Trojan & Botnet Loader

What this error means

This critical-severity issue affects the malware/security. Emotet is an advanced, modular banking trojan that operates primarily as a downloader or loader for other malware (such as TrickBot or Ryuk). It spreads through malicious email attachments (macros) and propagates laterally across networks. Work through the steps below in order.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Disable Microsoft Office macros by default via Group Policy

Disable Microsoft Office macros by default via Group Policy.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Run a complete offline security scan using Microsoft Defender

Run a complete offline security scan using Microsoft Defender.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Isolate infected machines from the local network

Isolate infected machines from the local network.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Implement email protection rules (DMARC, SPF, DKIM)

Implement email protection rules (DMARC, SPF, DKIM).

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Opening malicious email links or attachments with enabled macros
  • Weak administrative passwords enabling lateral network brute-force attacks
  • Lack of email spam filtering and macro execution restrictions