By January 2021, Emotet had been the internet's most reliable burglar for the better part of seven years. It began life in 2014 as a banking trojan and evolved into something more valuable: a loader, a service that broke into computers at scale and rented the open door to whoever paid — TrickBot, QakBot and the operators of Ryuk ransomware among the tenants. Its spam was mundane and effective: invoice lures, shipping notices and, in its cleverest touch, replies inserted into email threads the victim had genuinely taken part in. The FBI counted roughly 1.6 million infected computers worldwide between April 2020 and mid-January 2021, more than 45,000 of them in the United States. Europol used a plainer description: "the world's most dangerous malware."

The end was announced on 27 January 2021 and carried a code name, Operation Ladybird. Police and prosecutors from eight countries — the Netherlands, Germany, the United States, the United Kingdom, France, Lithuania, Canada and Ukraine, coordinated through Europol and Eurojust — had taken control of the botnet's command infrastructure from the inside, including two central servers in the Netherlands and seventeen more seized in Germany. In Kharkiv, Ukrainian officers raided properties tied to two men accused of maintaining that infrastructure, and released video of what they found: racks of hard drives, computer towers, bundles of banknotes and small gold bars. Ukraine's cyberpolice put Emotet's global damage at two and a half billion dollars and called even that conservative; the figure is police arithmetic, not a court's finding.

What distinguished Ladybird from earlier takedowns was what the police did with the controls once they held them. Infected machines checking in for instructions found themselves talking to law-enforcement servers, and the update channel that had distributed criminal payloads for years began serving a police-built module instead. It carried a date: on 25 April 2021 it would delete Emotet's services and autostart keys and quietly exit — removing the malware, and only the malware, from every machine that received it, while leaving whatever Emotet had already installed for its customers untouched. The state was acting, in effect, as an antivirus vendor of last resort. On the seized servers, Dutch investigators also found some 600,000 stolen email addresses and passwords, and opened a public lookup so victims could check for their own.

Nobody was arrested outside Ukraine, and the two Kharkiv suspects were described as maintainers rather than principals; the operators themselves, tracked for years by researchers under names like Mummy Spider, went unnamed. Nobody involved claimed the gang was finished, either. What the operation bought was a template: proof that a botnet's plumbing could be seized rather than merely blocked, and that the machinery of infection could be run backwards, once, under judicial order, to clean up after itself. Emotet's spam stopped that week, and the loader market lost its largest supplier overnight. How long the silence would hold was the question every press conference left open — and this archive, written five years on, has the advantage of knowing the answer.

Also that month · SolarWinds, act two

The fallout reaches the security industry

The SolarWinds story entered its attribution phase on 5 January, when the FBI, CISA, the NSA and the Office of the Director of National Intelligence issued a joint statement describing the campaign as the work of an advanced persistent threat actor likely Russian in origin — carefully worded, framed as intelligence gathering, and noting that of roughly 18,000 exposed Orion customers, fewer than ten US federal agencies had been compromised by follow-on activity. The rest of the month demonstrated that the actor's reach ran beyond SolarWinds' software. Mimecast disclosed on 12 January, after a warning from Microsoft, that a certificate used to connect its products to customers' Microsoft 365 tenants had been compromised; around ten per cent of its customers used the affected connection, and on 26 January the company confirmed the same actor was responsible. Malwarebytes followed on 19 January: the same group had read a limited subset of its internal email through abused privileged access to its Office 365 and Azure environments. Malwarebytes was not a SolarWinds customer at all — which was, quietly, the most unsettling detail of the month.

Also that month · Hunting the hunters

The blog that hacked its readers

On 25 January, Google's Threat Analysis Group described a campaign aimed not at banks or ministries but at the people who study such campaigns: a government-backed operation from North Korea targeting security researchers themselves. The actors built a plausible-looking research blog and a web of personas across Twitter, LinkedIn, Keybase and Telegram, complete with a YouTube video claiming to demonstrate an exploit for a genuine Windows Defender flaw — a video that careful viewers, including commenters beneath it, identified as faked. The approach was patient: praise a researcher's work, propose a collaboration, then send a Visual Studio project that executed a malicious DLL through its build events. The detail that unsettled the industry came last. Several researchers had been compromised merely by visiting the blog while running fully patched Windows 10 and up-to-date Chrome; Google said it could not confirm how — wording consistent with an unpatched browser flaw — and asked anyone with information to come forward. The people whose job is not to click had been beaten without clicking anything.

India desk · January 2021

JusPay: 35 million records, five months later

India's year opened with a breach that was five months old by the time the public learned of it. In the first days of January, independent researcher Rajshekhar Rajaharia reported that a large dataset from JusPay — the Bengaluru payments processor that handles card transactions for Amazon, Swiggy, MakeMyTrip and other consumer brands — was being offered on a dark-web forum, with threat-intelligence firm Cyble tracking the same trove; the asking price was reported at around $8,000 in bitcoin. Rajaharia put the haul at roughly 10 crore records. JusPay's confirmation followed within days and fixed the dates: the intrusion had occurred on 18 August 2020, through an old, unrecycled Amazon Web Services access key, and the company said it had detected and stopped it the same day. Compromise in August, disclosure in January — and only after the data surfaced for sale.

The researcher's numbers and the company's diverge, and this archive carries both. JusPay said about 3.5 crore — 35 million — records containing masked card data and card fingerprints were breached, stressing that the exposed digits — the first six and last four of sixteen — cannot complete a transaction, and that full card numbers, CVVs, PINs and passwords were never stored in the compromised store. It acknowledged separately that a slice of roughly 10 crore anonymised transaction-metadata records held plain-text email addresses and phone numbers. Rajaharia's reading was less comfortable: names, mobile numbers and bank names, searchable at scale — raw material for the scam calls that follow every Indian breach. No law obliged JusPay to notify affected users, and in January 2021 India had no data-protection statute; the DPDP Act was two and a half years from passage. India's pages in this archive begin with a leak its subjects learned about from a researcher's tweet.

AI Tech desk · January 2021

An armchair in the shape of an avocado

OpenAI opened the year with a research blog rather than a product. On 5 January 2021 it showed DALL·E, a 12-billion-parameter version of GPT-3 trained on text-image pairs to draw whatever a caption described; there was no public access, only curated samples, and one of them — an armchair in the shape of an avocado — did more for the idea of text-to-image generation than any paper had. Released alongside it, and openly, was CLIP, a network trained on 400 million image-text pairs to judge how well a picture fits a description. On 11 January, Google researchers published the Switch Transformer, a sparse design that pushed language models past a trillion parameters by routing each token to a single expert. Five years on, the footnote has outgrown the headline: DALL·E's descendants made image generation a consumer commodity within two years, but CLIP became the load-bearing component inside many of the systems that did it, and sparse routing is now ordinary in frontier models.

Digital Guard desk · January 2021

SonicWall, entered through its own appliance

On 22 January 2021, SonicWall — whose firewalls and remote-access appliances guard other organisations' networks — disclosed that what it called highly sophisticated threat actors had entered its internal systems through probable zero-day flaws in its own secure-access products. Suspicion settled on the SMA 100 series, and within a fortnight the flaw was confirmed, found being used against other customers, and patched, the company putting the exposed population at a few thousand appliances. That made three security vendors breached in a single month — Mimecast and Malwarebytes are chronicled above — but only SonicWall was entered through the product it sells. The month's quieter news was consolidation: on 8 January NortonLifeLock completed its roughly $360 million purchase of Avira, the German freemium house whose software sat on some thirty million devices, strongest in Europe. Seven months later came the far larger Avast merger that produced today's Gen Digital — and the SMA breach opened a half-decade in which the security appliance itself became the favoured way in.

⏳ Time capsule — January 2021

  • Donald Trump was impeached a second time on 13 January, a week after the storming of the US Capitol — the first American president impeached twice.
  • India launched the world's largest COVID-19 vaccination drive on 16 January, opening 3,006 centres on day one with Covishield and Covaxin.
  • Joe Biden was inaugurated as the 46th US president on 20 January; a photograph of Bernie Sanders, cross-armed in mittens, became the month's most shared image.
  • GameStop shares touched an intraday high of $483 on 28 January before Robinhood and other brokers restricted buying, capping the meme-stock squeeze's wildest week.
Where it stands today — 2026

The quiet lasted ten months

The uninstall fired on schedule on 25 April 2021, and for ten months Emotet was simply gone. Then, on 14 November 2021, researchers watched TrickBot — the old tenant — drop a fresh Emotet loader onto an infected machine, and the botnet rebuilt itself through 2022 before sputtering out after a last burst of spam in early 2023; it has not returned in any sustained form since. TrickBot itself was folded into Conti's orbit and died with Conti's 2022 collapse, chronicled elsewhere in these pages. But Ladybird's template outlived them all: covert control first, disruption second, visible again in the FBI's months inside Hive in January 2023, in the QakBot uninstaller of August 2023 — the Emotet play repeated almost line for line — and in LockBit's humiliation under Operation Cronos in February 2024.

The month's other threads run just as long. The actor behind SolarWinds, later renamed Midnight Blizzard, was still at work in January 2024, reading the mailboxes of Microsoft's own executives; North Korea's courtship of security researchers has been re-announced by Google, with fresh personas, at intervals ever since. JusPay's five-month silence became an argument for the breach-reporting clock CERT-In imposed in 2022 and the data-protection law India finally passed in 2023. And the Parler scrape of 10–11 January — some seventy terabytes lifted through an unauthenticated, sequentially numbered API before Amazon pulled the platform's hosting — opened the no-intrusion-required lineage this archive picks up with T-Mobile two years later. The Vault now begins here; the next restorations reach backwards, into December 2020, where the SolarWinds story itself starts.