Operation Endgame follow-up leads to five detentions and interrogations as well as server takedowns


Following the massive botnet takedown codenamed Operation Endgame in May 2024, which shut down the biggest malware droppers, including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, law enforcement agencies across North America and Europe dealt another blow to the malware ecosystem in early 2025.

In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet, operated by the actor known as ‘Superstar’, faced consequences such as arrests, house searches, arrest warrants or ‘knock and talks’. Superstar used his botnet to run a pay-per-install service, enabling customers to gain access to victims’ machines. Customers used the service to deploy malware for their own criminal activities. Investigations revealed that botnet access was purchased for a range of purposes, including keylogging, webcam access, ransomware deployment, cryptomining and more.

Read more…
Source: Europol


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • EU considers 60-minute deadline for social networks to remove terrorist content

    August 20, 2018

    No longer the carrot, now the stick: the European Commission is considering imposing an hour-long deadline for social networks to remove terrorist and extremist content after voluntary measures appear to have failed. As reported by the Financial Times on Sunday, Facebook, Twitter, and YouTube, as well as smaller businesses, are all within the EU’s sights. This is the first ...

  • FBI Warns Of ATM Hacking Campaign

    August 16, 2018

    The FBI has warned banks that cybercriminals are preparing to carry out a “highly choreographed, global fraud scheme known as an ‘ATM cash-out’.” The threat, reported by Krebs On Security cybersecurity blog, will apparently see criminals hacking a bank or payment card processor, and using cloned cards at ATMs around the world to fraudulently withdraw “millions of ...

  • Australia plans law for tech firms to hand over encrypted private data

    August 14, 2018

    Australia on Tuesday proposed a new law requiring technology firms such as Alphabet Inc’s Google, Facebook and Apple to give police access to private encrypted data linked to suspected illegal activities. The measure, which targets platforms the Australian government says could be used for criminal activities or to plan a terror attack, would require police to ...

  • FBI struggles to retain top cyber talent

    August 3, 2018

    The recent departures of four top FBI cyber officials reflect a troubling trend: The bureau is losing its most seasoned agents and supervisors tasked with disrupting digital threats from Russia and elsewhere, even as threats to the nation’s power grid and elections grow. Close to 20 top FBI cybersecurity leaders have left for high-paying corporate jobs over the ...

  • DOJ Nab Three FIN7 Cybercrime Suspects in Europe

    August 1, 2018

    Three people believed to be member of the FIN7 (or Carbanak) hacking group have been arrested in Europe, according to the US DOJ. Three suspected members of the FIN7 cybercrime group have been arrested in Europe and accused of hacking more than 120 U.S.-based companies with the intent of stealing bank cards. In total, U.S. Department of ...

  • Indictments Against 12 Russians Show How Hackers Were Hacked

    July 18, 2018

    Hi everybody, Jordan Robertson here. I cover cybersecurity in Washington, D.C. Today’s newsletter is about Special Counsel Robert Mueller’s indictment this week of 12 Russian military officers for allegedly orchestrating the hacks of the 2016 U.S. presidential election. The indictment, which I encourage you to read if you’re interested in technical details about how the hacks worked, is remarkable in a number ...