Updated Emotet toolkit ends 2020 as most dangerous malware
The banking trojan has climbed back to the top of Check Point's Global Threat Index


The Emotet Trojan was used to target over 100,000 users per day over December, placing it at the top of a list of the most dangerous malware threats facing businesses today.
That's according to a new global index from security research firm Check Point, which revealed the malware has impacted 7% of organisations around the world during the last month of 2020, closely followed by banking trojan Trickbot and information-stealing virus Formbook, both impacting 4% of global companies.
Is mobile malware really a risk? What is malware? What is ransomware?
All three viruses made a return to the index for December, although the sudden uptake of Emotet should be a cause for concern among businesses, Check Point has warned. It was originally developed as a banking malware, sneaking onto a target's computer to steal sensitive information, but it has since evolved into one of the most costly and destructive malware variants available, according to Maya Horowitz, director of threat intelligence and research products at Check Point.
"It's imperative that organisations are aware of the threat Emotet poses and that they have robust security systems in place to prevent a significant breach of their data," said Horowitz.
Emotet was at the top of the Global Threat Index in September and October, and is best known as being a tool for opening access to infected computers for further ransomware operations. It is also thought to have been used by the criminal group known as Ryuk, said to be responsible for a number of attacks on healthcare facilities throughout the autumn.
Researchers believe that a brief lull in activity during November was the moment the Emotet malware was updated with new payloads and improved detection capabilities. The Check Point team believes the malware is now far more dangerous as a result.
The same is true for Hiddad, an Android malware variant which repackages legitimate apps and then releases them to a third-party store. Its main function is to display ads, but it can also gain access to key security details built into the operating system.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The most exploited vulnerability of the month was the MVPower DVR Remote Code Execution flaw, which affected 42% of organisations around the world during the month.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Two years on from its Series B round, Hack the Box is targeting further growth
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott
-
Healthcare systems are rife with exploits — and ransomware gangs have noticed
News Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
By Nicole Kobie
-
Alleged LockBit developer extradited to the US
News A Russian-Israeli man has been extradited to the US amid accusations of being a key LockBit ransomware developer.
By Emma Woollacott
-
February was the worst month on record for ransomware attacks – and one threat group had a field day
News February 2025 was the worst month on record for the number of ransomware attacks, according to new research from Bitdefender.
By Emma Woollacott
-
CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted
News The Medusa ransomware as a Service operation compromised twice as many organizations at the start of 2025 compared to 2024
By Solomon Klappholz
-
Warning issued over prolific 'Ghost' ransomware group
News The Ghost ransomware group is known to act fast and exploit vulnerabilities in public-facing appliances
By Solomon Klappholz
-
The Zservers takedown is another big win for law enforcement
News LockBit has been dealt another blow by law enforcement after Dutch police took 127 of its servers offline
By Solomon Klappholz
-
There’s a new ransomware player on the scene: the ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry – and researchers warn it’s only going to get worse for potential victims
News Security experts have warned the BlackLock group could become the most active ransomware operator in 2025
By Solomon Klappholz