Europol: End of the game for cybercrime infrastructure: 1025 servers taken down


Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealers Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime.

Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was also arrested in Greece on 3 November 2025. The infrastructure dismantled during the action days was responsible for infecting hundreds of thousands of victims worldwide with malware. Operation Endgame, coordinated by Europol and Eurojust, is a joint effort between law enforcement and judicial authorities of Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the United Kingdom and the United States to tackle ransomware enablers.

Read more…
Source: Europol


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Storm-0501: Ransomware attacks expanding to hybrid cloud environments

    September 26, 2024

    Microsoft has observed the threat actor tracked as Storm-0501 launching a multi-staged attack where they compromised hybrid cloud environments and performed lateral movement from on-premises to cloud environment, leading to data exfiltration, credential theft, tampering, persistent backdoor access, and ransomware deployment. The said attack targeted multiple sectors in the United States, including government, manufacturing, transportation, and ...

  • Telegram CEO Durov Says App to Provide More Data to Governments

    September 23, 2024

    Messaging app Telegram will provide users’ IP addresses and phone numbers to relevant authorities in response to valid legal requests, according to Chief Executive Officer Pavel Durov. The platform changed its terms of service to deter criminals from abusing it, Durov said in a post on Telegram Monday. The move comes less than a month after ...

  • Internet surveillance firm Sandvine says it’s leaving 56 ‘non-democratic’ countries

    September 20, 2024

    Sandvine, the makers of surveillance-ware that allowed authoritarian countries to censor the internet and spy on their citizens, announced that it is leaving dozens of “non-democratic” countries as part of a major overhaul of the company. The company, which was founded in Canada, published a statement on Thursday, claiming that it now wants to be “a ...

  • Cyber attack on city of Wichita limited to police records, internal investigation finds

    September 19, 2024

    A ransomware attack that crippled the city of Wichita’s network for more than a month starting in May was limited to a Wichita Police Department records system, city officials said Wednesday. That means the Russian hacker group — LockBit — that claimed credit for the attack did not access bank card numbers, social security numbers or ...

  • Tor anonymity compromised by law enforcement. Is it still safe to use?

    September 19, 2024

    Despite people generally considering the Tor network as an essential tool for anonymous browsing, german law enforcement agencies have managed to de-anonymize Tor users after putting surveillance on Tor servers for months. German news outlet NDR reports that law enforcement agencies got hold of data while performing server surveillance which was processed in such a way ...

  • Teenager arrested following cyber attack on Transport for London

    September 13, 2024

    A 17-year-old boy has been arrested following a cyber attack on Transport for London. Hackers may have accessed the bank details and home addresses of at least 5,000 customers, TfL admitted on Thursday. The Information Commissioner has been informed. National Crime Agency officers said they had arrested a teenager from Walsall, in the West Midlands, on ...