Operation Endgame follow-up leads to five detentions and interrogations as well as server takedowns


Following the massive botnet takedown codenamed Operation Endgame in May 2024, which shut down the biggest malware droppers, including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, law enforcement agencies across North America and Europe dealt another blow to the malware ecosystem in early 2025.

In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet, operated by the actor known as ‘Superstar’, faced consequences such as arrests, house searches, arrest warrants or ‘knock and talks’. Superstar used his botnet to run a pay-per-install service, enabling customers to gain access to victims’ machines. Customers used the service to deploy malware for their own criminal activities. Investigations revealed that botnet access was purchased for a range of purposes, including keylogging, webcam access, ransomware deployment, cryptomining and more.

Read more…
Source: Europol


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Police Service Northern Ireland had 260 data breaches in two years, with only a fraction reported or disclosed

    June 12, 2024

    Figures released under a Freedom of Information request have shown the PSNI had 260 data breaches over two years — but only a fraction of them were reported to external authorities, and even fewer were publicly disclosed. In one case, a data breach was not reported for almost eight years. In 2022, there were 154 breaches, ...

  • Thousands detained as Thailand ramps up cybercrime suppression campaign

    June 10, 2024

    The Ministry of Digital Economy and Society (MDES) is intensifying its efforts to combat cybercrime. It reported a significant increase in access blocks to gambling websites and the closure of millions of suspicious mobile lines last month. The Ministry of Digital Economy and Society (MDES) has been taking strong measures to combat cybercrime, particularly in the ...

  • FBI urges LockBit ransomware victims to reach out after securing thousands of decryption keys

    June 7, 2024

    The FBI revealed it has thousands of decryption keys that can unlock data encrypted by the LockBit ransomware. The agency’s Assistant Director for the Cyber Division, Bryan Vorndran, confirmed the news during the 2024 Boston Conference on Cyber Security, and has invited all past LockBit victims to reach out and try to unlock their files. Read more… Source: ...

  • Telangana Police hit by second major data breach in a week as TSCOP App compromised

    June 7, 2024

    Just a week after the hacking incident involving Telangana police’s HawkEye app, another app, TSCOP, has been compromised as well. As a result, policerelated data is currently available for sale on online forums. The same hacker responsible for the breach of HawkEye is behind this security lapse. The TSCOP app user data is being sold online ...

  • Chinese Nationals Plead Guilty To Cyber Crimes In Zambia

    June 5, 2024

    Twenty-two Chinese nationals have pleaded guilty to committing cyber-related crimes in Zambia. They are among 77 suspects arrested in April in connection with a “sophisticated internet fraud syndicate,” according to authorities. The operation targeted a Chinese-run company in Lusaka following a surge in internet fraud cases affecting people globally. The Chinese nationals are scheduled for sentencing ...

  • Scammers Defraud Individuals via Work-From-Home Scams

    June 4, 2024

    The FBI warns of scammers offering victims fake work-from-home jobs, typically involving a relatively simple task, such as rating restaurants or “optimizing” a service by repeatedly clicking a button. The scammers pose as a legitimate business, such as a staffing or recruiting agency,and may contact victims via an unsolicited call or message. Scammers design the fake ...