Europol: End of the game for cybercrime infrastructure: 1025 servers taken down


Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol’s headquarters in The Hague. The actions targeted one of the biggest infostealers Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime.

Authorities took down these three large cybercrime enablers. The main suspect for VenomRAT was also arrested in Greece on 3 November 2025. The infrastructure dismantled during the action days was responsible for infecting hundreds of thousands of victims worldwide with malware. Operation Endgame, coordinated by Europol and Eurojust, is a joint effort between law enforcement and judicial authorities of Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the United Kingdom and the United States to tackle ransomware enablers.

Read more…
Source: Europol


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Thousands detained as Thailand ramps up cybercrime suppression campaign

    June 10, 2024

    The Ministry of Digital Economy and Society (MDES) is intensifying its efforts to combat cybercrime. It reported a significant increase in access blocks to gambling websites and the closure of millions of suspicious mobile lines last month. The Ministry of Digital Economy and Society (MDES) has been taking strong measures to combat cybercrime, particularly in the ...

  • FBI urges LockBit ransomware victims to reach out after securing thousands of decryption keys

    June 7, 2024

    The FBI revealed it has thousands of decryption keys that can unlock data encrypted by the LockBit ransomware. The agency’s Assistant Director for the Cyber Division, Bryan Vorndran, confirmed the news during the 2024 Boston Conference on Cyber Security, and has invited all past LockBit victims to reach out and try to unlock their files. Read more… Source: ...

  • Telangana Police hit by second major data breach in a week as TSCOP App compromised

    June 7, 2024

    Just a week after the hacking incident involving Telangana police’s HawkEye app, another app, TSCOP, has been compromised as well. As a result, policerelated data is currently available for sale on online forums. The same hacker responsible for the breach of HawkEye is behind this security lapse. The TSCOP app user data is being sold online ...

  • Chinese Nationals Plead Guilty To Cyber Crimes In Zambia

    June 5, 2024

    Twenty-two Chinese nationals have pleaded guilty to committing cyber-related crimes in Zambia. They are among 77 suspects arrested in April in connection with a “sophisticated internet fraud syndicate,” according to authorities. The operation targeted a Chinese-run company in Lusaka following a surge in internet fraud cases affecting people globally. The Chinese nationals are scheduled for sentencing ...

  • Scammers Defraud Individuals via Work-From-Home Scams

    June 4, 2024

    The FBI warns of scammers offering victims fake work-from-home jobs, typically involving a relatively simple task, such as rating restaurants or “optimizing” a service by repeatedly clicking a button. The scammers pose as a legitimate business, such as a staffing or recruiting agency,and may contact victims via an unsolicited call or message. Scammers design the fake ...

  • UK: The Princess of Wales’s hospital data breach not referred to police due to suspected ‘decoy’ plan

    June 3, 2024

    The Princess of Wales’s hospital data breach has not been referred to police as an expert explains that a “decoy” plan could have been in use – meaning her actual medical files were not accessed by the perpetrators. Despite Health Minister Maria Caulfield revealing back in March that the police had been asked to look into ...