Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Darktrace AI stops Emotet trojan cyber-attack

Security

Darktrace AI stops Emotet trojan cyber-attack

Cambridge based Darktrace announced today that its Autonomous Response technology, Antigena, successfully took action to halt a recent cyber-attack targeting a construction supply enterprise in Saudi Arabia.

Image copyright Shutterstock

The company, which has been in business for over 50 years and has over 35 branches, was infiltrated by attackers in the early hours of the morning. Darktrace's Self-Learning AI spotted that a company device was compromised by Emotet, an infamous trojan that rapidly spreads malware from device to device, exfiltrating sensitive financial information. Emotet, which had defeated static security controls in the organisation, is often the pre-cursor to ransomware if left uninterrupted.

Advertisement
Leonardo animated rectangle

Within minutes, Darktrace AI took action to successfully block malicious communications occurring between the infected device and an unusual host.

Self-Learning AI formed a constantly evolving understanding of both IT and operational technologies at the Saudi Arabian construction giant, allowing it to identify the subtle, emerging signs of Emotet. Within seconds, the algorithms took targeted action to interrupt the encroaching attack. This allowed the organisation to continue normal business operations without disruption and investigate the incident further.

The attack occurred amidst rising global cyber tensions and follows warnings from the Five Eyes urging companies to bolster defenses – particularly operators of critical national infrastructure or organisations that are critical to global supply chains.

"Since its emergence in 2014 the Emotet trojan has undergone multiple iterations and recently made a comeback globally," commented Max Heinemeyer, Director of Threat Hunting at Darktrace. "Emotet is particularly dangerous because this type of botnet can quickly escalate into something like ransomware if not stopped. Business leaders should know there is technology out there that can stop these attacks in their tracks, before sensitive data leaves the organization and before any ransom is demanded."
 

Advertisement
ODU RT

 

 

Advertisement
Babcock LB Babcock LB
JFD Global to enhance Polish Navy

Defence Security

JFD Global to enhance Polish Navy's submarine rescue capability

11 December 2025

James Fisher (JFD Global) has secured a contract with PGZ Stocznia Wojenna, which will see JFD Global integrate a combined, hyperbaric and saturation diving system into the Polish Navy’s new salvage and rescue vessel, Ratownik.

RISC appoints Paul Lincoln as Chair

Security

RISC appoints Paul Lincoln as Chair

11 December 2025

The Security and Resilience Industry Suppliers Community (RISC), today announces the appointment of Paul Lincoln CB OBE VR as its new Chair.

Avon Protection receives European order for FM50 respirators

Defence Security

Avon Protection receives European order for FM50 respirators

11 December 2025

Avon Protection has received a new European order for FM50 respirators and FM61EU filters via the NATO Support and Procurement Agency (NSPA) contract vehicle.

Babcock delivers LFB’s first fully electric lorries

Security

Babcock delivers LFB’s first fully electric lorries

10 December 2025

Babcock has marked a major milestone in its partnership with London Fire Brigade (LFB) by supplying the service with its first fully electric large goods vehicles (eLGVs) making LFB the first fire service in the UK to use a fully electric fleet for training.

Advertisement
Leonardo animated rectangle
UK prison building programme continues expansion

Security

UK prison building programme continues expansion

10 December 2025

As part of Government action to keep the public safe and ensure jails never run out of space again, around 5,000 new prison places are under construction in the biggest jail expansion programme since the Victorian era, including in the North West, South East, South West and East of England.

Cobham Satcom and Gatehouse Satcom

Defence Security Space

Cobham Satcom and Gatehouse Satcom's Network Division to merge

8 December 2025

Cobham Satcom and Gatehouse Satcom today announced a strategic merger between Gatehouse Satcom and Cobham Satcom’s Network Division.

Advertisement
ODU RT