Operation Endgame follow-up leads to five detentions and interrogations as well as server takedowns


Following the massive botnet takedown codenamed Operation Endgame in May 2024, which shut down the biggest malware droppers, including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, law enforcement agencies across North America and Europe dealt another blow to the malware ecosystem in early 2025.

In a coordinated series of actions, customers of the Smokeloader pay-per-install botnet, operated by the actor known as ‘Superstar’, faced consequences such as arrests, house searches, arrest warrants or ‘knock and talks’. Superstar used his botnet to run a pay-per-install service, enabling customers to gain access to victims’ machines. Customers used the service to deploy malware for their own criminal activities. Investigations revealed that botnet access was purchased for a range of purposes, including keylogging, webcam access, ransomware deployment, cryptomining and more.

Read more…
Source: Europol


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • DoppelPaymer ransomware group suspects identified

    September 20, 2023

    The German police in cooperation with the US Secret Service have executed search warrants against suspected members of the DoppelPaymer ransomware group in Germany and Ukraine. In March of 2023 the German Regional Police and the Ukrainian National Police, with support from Europol, the Dutch Police, and the United States Federal Bureau of Investigations (FBI), apprehended ...

  • One of the FBI’s most wanted hackers is trolling the U.S. government

    September 18, 2023

    Earlier this year, the U.S. government indicted Russian hacker Mikhail Matveev, also known by his online monikers “Wazawaka” and “Boriselcin,” accusing him of being “a prolific ransomware affiliate” who carried out “significant attacks” against companies and critical infrastructure in the U.S. and elsewhere. The feds also accused him of being a “central figure” in the development ...

  • UK: Greater Manchester Police officers’ details hacked in cyber attack

    September 14, 2023

    Police officers’ personal details have been hacked after a company was targeted in a cyber attack. The firm in Stockport, which makes ID cards, holds information on various UK organisations including some of the staff employed by Greater Manchester Police (GMP). The force confirmed it was aware of the ransomware attack. The hack means thousands of ...

  • 11 alleged Conti criminals hit with UK and US sanctions

    September 8, 2023

    UK and US authorities have issued sanctions on 11 individuals who are allegedly part of a cybercriminal gang that use Trickbot and Conti malware. The 11 individuals have been hit with asset freezes and travel bans in a coordinated effort to counter the threat of ransomware, according to UK officials. The country’s National Crime Agency (NCA) ...

  • PSNI data breach: Two men released after Terrorism Act arrests

    September 3, 2023

    Two men have been released after being arrested by detectives investigating a major data breach by the Police Service of Northern Ireland (PSNI). The data was accidentally shared in August and included the surname and initials of 10,000 PSNI employees. The men, aged 21 and 22, were arrested under the Terrorism Act after a search in ...

  • US charges crypto founders over alleged support for North Korean hackers

    August 24, 2023

    The United States has charged two cofounders of the cryptocurrency mixer Tornado Cash with money laundering and other crimes a year after authorities banned the Russian-founded platform over its alleged support of North Korean hackers. Roman Semenov and Roman Storm have been charged with conspiracy to commit money laundering, conspiracy to commit sanctions violations, and conspiracy ...