Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Darktrace AI stops Emotet trojan cyber-attack

Security

Darktrace AI stops Emotet trojan cyber-attack

Cambridge based Darktrace announced today that its Autonomous Response technology, Antigena, successfully took action to halt a recent cyber-attack targeting a construction supply enterprise in Saudi Arabia.

Image copyright Shutterstock

The company, which has been in business for over 50 years and has over 35 branches, was infiltrated by attackers in the early hours of the morning. Darktrace's Self-Learning AI spotted that a company device was compromised by Emotet, an infamous trojan that rapidly spreads malware from device to device, exfiltrating sensitive financial information. Emotet, which had defeated static security controls in the organisation, is often the pre-cursor to ransomware if left uninterrupted.

Advertisement
PTC rectangle

Within minutes, Darktrace AI took action to successfully block malicious communications occurring between the infected device and an unusual host.

Self-Learning AI formed a constantly evolving understanding of both IT and operational technologies at the Saudi Arabian construction giant, allowing it to identify the subtle, emerging signs of Emotet. Within seconds, the algorithms took targeted action to interrupt the encroaching attack. This allowed the organisation to continue normal business operations without disruption and investigate the incident further.

The attack occurred amidst rising global cyber tensions and follows warnings from the Five Eyes urging companies to bolster defenses – particularly operators of critical national infrastructure or organisations that are critical to global supply chains.

"Since its emergence in 2014 the Emotet trojan has undergone multiple iterations and recently made a comeback globally," commented Max Heinemeyer, Director of Threat Hunting at Darktrace. "Emotet is particularly dangerous because this type of botnet can quickly escalate into something like ransomware if not stopped. Business leaders should know there is technology out there that can stop these attacks in their tracks, before sensitive data leaves the organization and before any ransom is demanded."
 

Advertisement
Security & Policing Rectangle

 

 

Advertisement
ECS leaderboard banner
Smith Myers expands ARTEMIS capability

Aerospace Defence Security

Smith Myers expands ARTEMIS capability

5 March 2026

Smith Myers Communications Ltd. today announced the addition of passive Wi-Fi and Bluetooth detection and geolocation capability, together with ATAK Cursor-on-Target (CoT) integration, expanding the capability of its ARTEMIS system.

Respect the Range access rules strengthen UK Defence

Defence Security

Respect the Range access rules strengthen UK Defence

5 March 2026

The Ministry of Defence (MoD) is reminding the public to follow safe access rules when visiting military training areas, to keep everyone safe and avoid disrupting training.

Cambridge Pixel set to introduce HPx-700

Aerospace Defence Security

Cambridge Pixel set to introduce HPx-700

4 March 2026

Cambridge Pixel has revealed that it will be introducing its new HPx-700, an ARM-based embedded Radar Input & Signal Processor, with the advanced radar system solution becoming available from next month.

Kahootz expands into Japan to enhance cybersecurity

Security Events

Kahootz expands into Japan to enhance cybersecurity

4 March 2026

As the UK and Japan draw closer as partners to strengthen collective security, Kahootz is expanding its presence into Japan to support UK-Japan collaboration and to provide the necessary software to protect against malign actors looking to attack a partner nation.

Advertisement
ODU RT
Viasat and Galaxy 1 to enhance Velaris

Aerospace Security Space

Viasat and Galaxy 1 to enhance Velaris

3 March 2026

Galaxy 1 Communications is working with Viasat to enhance delivery of Velaris, Viasat’s dedicated satellite communications service for Uncrewed Aerial Vehicles (UAVs) and Advanced Air Mobility (AAM) aircraft.

Cyacomb introduces Similarity Matching

Security

Cyacomb introduces Similarity Matching

3 March 2026

Edinburgh based digital triage experts, Cyacomb, today announced the availability of a new Similarity Matching capability within its Examiner Plus platform, enabling law enforcement to identify Child Sexual Abuse Material (CSAM) on mobile devices in minutes, even when images have been shared via messaging applications and altered from their ...

Advertisement
ODU RT
Advertisement
ECS leaderboard banner