Europol: End of the game for cybercrime infrastructure: 1025 servers taken down


Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealers Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime.

Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was also arrested in Greece on 3 November 2025. The infrastructure dismantled during the action days was responsible for infecting hundreds of thousands of victims worldwide with malware. Operation Endgame, coordinated by Europol and Eurojust, is a joint effort between law enforcement and judicial authorities of Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the United Kingdom and the United States to tackle ransomware enablers.

Read more…
Source: Europol


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Ex-US Air Force intelligence officer charged with spying for Iran

    February 14, 2019

    U.S. authorities on Wednesday charged former Air Force intelligence officer Monica Witt with helping Iran launch a cyber-spying operation that targeted her former colleagues after she defected from the United States. The U.S. Justice Department said Witt, 39, assembled dossiers on eight U.S. military intelligence agents she had worked with for Iranian hackers, who then used Facebook and ...

  • FBI arrests second Apophis Squad hacker in the US

    February 13, 2019

    The FBI arrested yesterday a hacker part of a hacking team known as Apophis Squad. This is the second arrest of an Apophis Squad member after UK cops arrested a teenager in August 2018. The two, US and UK citizens, respectively, have been charged in an indictment unsealed by the US Department of Justice yesterday. They stand ...

  • Counter-Terrorism and Border Security Bill given Royal Assent

    February 12, 2019

    New laws which gives the give the UK greater powers to crackdown on hostile state activity, have today received Royal Assent. The Counter-Terrorism and Border Security Act 2019 also ensures sentencing for certain terrorism offences can properly reflect the severity of the crimes, as well as preventing re-offending and disrupting terrorist activity more rapidly. In addition, the act updates ...

  • Cyber exercise shows need for closer federal-state coordination

    February 6, 2019

    An attack by bad guys online and on the ground on a big city’s critical infrastructure can straddle jurisdictional lines between local and federal authorities, making coordination among those groups critical but tricky, according to participants in a recent resilience exercise. “We’re outgunned when it comes to nation-state cyberattacks” that could target cyber and physical targets ...

  • FBI Mapping ‘Joanap Malware’ Victims to Disrupt the North Korean Botnet

    January 31, 2019

    The United States Department of Justice (DoJ) announced Wednesday its effort to “map and further disrupt” a botnet tied to North Korea that has infected numerous Microsoft Windows computers across the globe over the last decade. Dubbed Joanap, the botnet is believed to be part of “Hidden Cobra“—an Advanced Persistent Threat (APT) actors’ group often known as ...

  • Users of illegal websites targeted in joint law-enforcement activity

    January 29, 2019

    The National Crime Agency, working with law enforcement partners from 14 countries, has taken action against a number of cyber criminals website users linked to four million attacks across the globe. This latest action is part of Operation Power Off, which pursues those individuals and services responsible for committing or facilitating DDoS (Distributed Denial of Service) ...