Operation Endgame follow-up leads to five detentions and interrogations as well as server takedowns


Following the massive botnet takedown codenamed Operation Endgame in May 2024, which shut down the biggest malware droppers, including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, law enforcement agencies across North America and Europe dealt another blow to the malware ecosystem in early 2025.

In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet, operated by the actor known as ‘Superstar’, faced consequences such as arrests, house searches, arrest warrants or ‘knock and talks’. Superstar used his botnet to run a pay-per-install service, enabling customers to gain access to victims’ machines. Customers used the service to deploy malware for their own criminal activities. Investigations revealed that botnet access was purchased for a range of purposes, including keylogging, webcam access, ransomware deployment, cryptomining and more.

Read more…
Source: Europol


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Sweden data leak ‘a disaster’, says PM

    July 24, 2017

    The Swedish government has admitted to a huge data leak made by one of its own departments during an IT outsourcing procedure in 2015. Sweden’s prime minister said it was “a disaster”, Swedish media reported. Reports say that confidential data about military personnel, along with defence plans and witness protection details, were exposed by the Transport Agency. They ...

  • Massive blow to criminal Dark Web activities after globally coordinated operation

    July 20, 2017

    Two major law enforcement operations, led by the Federal Bureau of Investigation (FBI), the US Drug Enforcement Agency (DEA) and the Dutch National Police, with the support of Europol, have shut down the infrastructure of an underground criminal economy responsible for the trading of over 350 000 illicit commodities including drugs, firearms and cybercrime malware. ...

  • Inspector gadget: how smart devices are outsmarting criminals

    June 23, 2017

    Richard Dabate told police a masked intruder assaulted him and killed his wife in their Connecticut home. His wife’s Fitbit told another story and Dabate was charged with the murder. James Bates said an acquaintance accidentally drowned in his hot tub in Arkansas. Detectives suspected foul play and obtained data from Bates’s Amazon Echo device. Bates ...

  • German police nick alleged admin of dark web gun sales site

    June 12, 2017

    German police have arrested a man they suspect of being the administrator of a dark net website. The site is said to have been used to buy a gun used in a 2016 mass murder. The unnamed 30-year-old man was arrested on 8 June in “south west Germany”, according to Sky News. The server used to host ...

  • Infrastructure Software Vulnerabilities Raise Concern Among Cybersecurity Experts

    June 9, 2017

    Vulnerabilities in software that automates everything from factories to traffic lights has become the nation’s top cybersecurity threat, an agent on the FBI’s Denver Cyber Task Force said Thursday in Colorado Springs. Supervisory control and data acquisition software is used to control — sometimes remotely — many types of devices in the energy, transportation, manufacturing and ...

  • Investigatory Powers Act: Back doors, black boxes, and tech capability regs

    May 8, 2017

    The Home Office has launched an under-the-radar consultation on a critical step in the implementation of the Investigatory Powers Act (IP Act): the regulations on technical capability notices. The Open Rights Group has recently revealed details of the proposed regulations. Under the IP Act, a technical capability notice can be issued to a telecommunications operator by the secretary of state ...