Operation Endgame 3.0 push takes down more cybercrime servers, disrupting criminal gangs

  • Europol disrupts Rhadamanthys, VenomRAT, and Elysium, seizing servers, domains, and arresting one suspect
  • The malware infrastructure held millions of stolen credentials and over 100,000 crypto wallets
  • Operation Endgame previously dismantled major malware networks, though some like DanaBot have resurfaced

Europol has launched the latest phase of its Operation Endgame, looking to disrupt the activities of some of the largest malware operations active today.

A press release published on Europol’s website claims between November 10 and 13 its agents, together with national law enforcement agencies from a handful of European countries, disrupted Rhadamanthys, VenomRAT, and Elysium.

The activities resulted in more than 1,000 servers either taken down or disrupted, 20 domains seized, and 11 locations searched (one in Germany and Greece, and nine in the Netherlands). Furthermore, one person was arrested, suspected of operating VenomRAT.

Europol’s activities

The dismantled malware infrastructure consisted of “hundreds of thousands of infected computers containing several million stolen credentials,” Europol explained.

Many of the victims were oblivious to the fact they were targeted, it added, and said that the main suspect behind the infostealer had access to “over 100,000 crypto wallets” potentially worth millions.

News of the operation first surfaced two days ago, when independent security researchers saw Rhadamanthys’ users being locked out of the platform. Those users, as well as the malware’s operators, blamed the German authorities for the disruption, and urged their users to cover up their tracks.

Operation Endgame’s last activity was in May 2025, when Europol and Eurojust dismantled a ransomware kill chain. In that operation, the police seized roughly 300 servers, took down 650 domains, and issued international arrest warrants against 20 individuals. The police also seized €3.5 million in various cryptocurrencies.

Disrupting malware operations is commendable, but without arrests, it is only a matter of time before they resurface. DanaBot, one of operations that were taken down in May, resurfaced six months later, with rebuilt infrastructure and new cryptocurrency wallets to siphon stolen funds to.

Other backdoor, malware, and loader operations that were disrupted through Operation Endgame include IcedID, Smokeloader, Qakbot, and Trickbot.

Via Infosecurity Magazine

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Apple sues OpenAI for allegedly stealing hardware secrets

Apple has sued OpenAI, alleging that engineers stole Apple secrets to advance the AI startup's hardware plans. In its complaint, Apple says it uncovered...

The FCC is cracking down on DJI tech that dodged the foreign drone ban

The Xtra Muse and the DJI Osmo Pocket 3. | Photo by Sean Hollister / The Verge Last year, we told you about Xtra, the...

Meta turns off the Instagram feature that let users make AI deepfakes of public accounts

Following significant backlash, Meta is turning off the feature it announced this week that let users generate AI images based on content from public...

No, Flock isn’t threatening people for debating surveillance

On Thursday, the Instagram account for a lecture series in Newport Beach, CA posted a photo of what appeared to be a cease and...

Netflix is turning into YouTube

Netflix has shows and movies. And video games. And live sports. And podcasts. And also, apparently, YouTube videos? For a company that used to...

Spotify will let you fine-tune your weekly Release Radar playlist

Spotify is giving listeners control to fine-tune what gets surfaced for them in Release Radar - one of its most popular weekly playlists. The...

Nvidia’s biggest RAM supplier just had a trillion-dollar debut on Wall Street

SK Hynix CEO Kwak Noh-Jung. | Image: Michael Nagle/Bloomberg via Getty Images As the AI boom boosts demand for RAM, SK Hynix - one of...

ICE is threatening to deport witnesses of its latest shooting

Department of Homeland Security. | Image: The Verge Advocates are demanding that the Department of Homeland Security release bodycam footage of the fatal shooting of...

A decade later, Pokémon Go finally made good on its original promise

When Niantic dropped the first Pokémon Go trailer in 2015, it was hard to grasp how a bunch of players could work together to...

What went wrong with OnePlus? [Video]

From a darling of the early Android era to a husk on the brink of becoming completely irrelevant, just what went wrong for OnePlus? Read...