US, UK, and EU law enforcement shuts down Dridex banking malware that stole $31M from UK bank accounts
Katie Collins / CNET :
Context & Ripple Effects
This 2015 operation is where the Dridex arc starts: US, UK, and EU agencies seize the banking malware's infrastructure after it drained $31M from UK accounts. The related coverage shows what came next — four years later the DOJ charged two members of Evil Corp, the Russian gang behind Dridex, alleging over $100M stolen and hitting them with US Treasury sanctions.
Read forward, the takedown reads as an early template rather than a one-off: the same multi-agency model reappears in the 11-country LockBit seizure of 11K domains and Europol's botnet takedowns spreading ransomware via infected email, with Germany, the FBI, and Ukraine disrupting a DoppelPaymer-deploying gang along the way.
First-order effects
- UK bank customers hit by Dridex lose the active infection channel overnight, as the botnet infrastructure used to push credentials-stealing updates is taken offline.
- Evil Corp's operators face their first major operational setback, though the corpus shows the group kept operating — the 2019 DOJ charges allege $100M+ stolen after this shutdown.
Second-order effects
- Gangs that survive takedowns shift business models rather than disband — Evil Corp's later evolution into ransomware operations like DoppelPaymer shows banking malware crews migrating to extorting companies directly.
- Each successful joint operation raises the coordination bar for the next one, pulling more national agencies into ad hoc coalitions like the 11-country LockBit action.
Third-order effects
- If the pattern holds, cybercrime enforcement consolidates around recurring multinational seizure-plus-indictment campaigns, making sanctions and named-gang charges standard follow-ons to infrastructure takedowns.
- The persistence of Evil Corp across a decade of coverage suggests takedowns degrade but rarely eliminate top-tier Russian-speaking crews, pushing policy toward financial pressure alongside technical disruption.
The trend: Cybercrime enforcement has evolved from single-country takedowns like the 2015 Dridex seizure into standing multinational campaigns that pair domain seizures with indictments and Treasury sanctions against named gangs.