Europol says police in Germany, the UK, the US, and others took down botnets spreading ransomware via infected emails, arrested four, and seized 2,000+ domains
Police coordinated by the European Union's justice and police agencies have taken down computer networks responsible …
Associated Press Mike Corder
Context & Ripple Effects
The operation extends a recurring Europol-led model: cross-border agencies target both ransomware operators and the infrastructure that delivers or supports their campaigns. A prior seizure of Emotet's infrastructure showed the same emphasis on disrupting malware operations from inside their technical footprint.
It also follows the disruption of a DoppelPaymer-linked ransomware gang, reinforcing that international cases increasingly combine technical takedowns with arrests rather than treating them as separate actions.
First-order effects
- The seized domains and dismantled botnets immediately remove identified email-based ransomware delivery infrastructure from the operators' control.
- Four arrests give investigators potential access to operational evidence and disrupt the people tied to the campaign, while affected organizations gain a break from the identified distribution network.
Second-order effects
- Operators behind the campaign must replace domains and rebuild delivery infrastructure before they can resume a comparable email-based operation, raising the operational cost of the campaign.
- Security teams can use indicators associated with the seized infrastructure to hunt for prior exposure and tighten email controls, though a takedown does not by itself remove infections already present on endpoints.
Third-order effects
- If these coordinated seizures continue, ransomware enforcement will increasingly depend on denying criminals access to the domains and botnet infrastructure that make campaigns scalable, alongside pursuing individual suspects.
- The pattern may favor more durable international coordination: operators can relocate, but infrastructure and evidence often span jurisdictions, making unilateral enforcement less effective.
The trend: Ransomware enforcement is shifting toward coordinated disruption of the technical delivery layer as well as arrests of the people operating it.
Related: Europol · Germany · Europol and partners seize Emotet infrastructure · Police disrupt DoppelPaymer-linked ransomware gang · International authorities arrest ransomware-group members
Related Coverage
- Largest ever operation against botnets hits dropper malware ecosystem Europol
- Welcome to The Endgame — International law enforcement and partners have joined forces. Operation Endgame
- U.S. And Europol Take Down Two Huge Botnets Forbes · Emma Woollacott
- Police seize over 100 malware loader servers, arrest four cybercriminals BleepingComputer · Bill Toulas
- Operation Endgame, the largest law enforcement operation ever against botnets Security Affairs · Pierluigi Paganini
- Operation Endgame — Today we loaded 16.5M email addresses and 13.5M unique passwords provided … Troy Hunt
- Europol Shuts Down 100+ Servers Linked to IcedID, TrickBot, and Other Malware The Hacker News
- Major malware droppers disrupted, four suspects arrested - Europol Cybernews.com · Vilius Petkauskas
- Four arrested in sprawling European sting on malware network Reuters · Rachel More
- Four arrested in major international anti-malware sting Le Monde.fr
- New breach: Operation Endgame involved a coalition of international law enforcement agencies dismantling a series of botnets. Impacted email addresses & passwords were provided to HIBP to help victims learn of exposure. 72% were already in @haveibeenpwned https://www.troyhunt.com/... @haveibeenpwned@infosec.exchange
- We are proud to announce that we assisted the joint international law enforcement operation #OperationEndgame, targeting the notorious botnets #IcedID, #Smokeloader, #SystemBC and #Pikabot 🔥 — abuse.ch has provided key infrastructure to LEA and internal partners to disrupt these botnet operations 🛑 … @abuse_ch@ioc.exchange
- 911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation US Department of Justice
- World's largest botnet seized in Federal bust, Chinese national arrested CSO · Shweta Sharma
- Chinese national cuffed on charges of running 'likely the world's largest botnet ever' The Register · Brandon Vigliarolo
- Sports cars and millions seized in cybercrime busts BBC
- US DOJ says Chinese national arrested on malware charges in international operation Reuters · Xinghui Kok
- US arrests man allegedly behind enormous botnet that enabled cyberattacks and fraud The Verge · Lauren Feiner
- Treasury Sanctions Creators of 911 S5 Proxy Botnet Krebs on Security · Brian Krebs
- International Authorities Arrest Man Allegedly Behind 'Likely the World's Largest Botnet Ever' Associated Press
- Guidance on the 911 S5 Residential Proxy Service IC3.gov News
- US-Led Operation Takes Down World's Largest Botnet Infosecurity · James Coker
- US dismantles 'world's largest botnet ever' that infected 19mln IP addresses Proactive
- 'World's largest botnet': US nabs Chinese man who hacked 19 million PCs Interesting Engineering · Sujita Sinha
- Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested SecurityWeek · Eduard Kovacs
- Department of Justice says it has taken down a large botnet with 19M unique IP address SiliconANGLE · Duncan Riley
- US Department of Justice smashes 911 S5 botnet run by Chinese national Neowin · Paul Hill
- U.S. Dismantles World's Largest 911 S5 Botnet, with 19 Million Infected Devices The Hacker News
- US Arrests Chinese Citizen Behind Malicious VPNs That Infected Millions PCMag · Michael Kan
- The US Treasury sanctions three Chinese nationals and three Thailand-based companies linked to a botnet controlling residential proxy service “911 S5” BleepingComputer · Sergiu Gatlan
- Cloudrouter homepage now features seizure notice from DOJ — [image] @briankrebs@infosec.exchange · BrianKrebs
- The DOJ just announced they indicted and arrested Wang, the alleged owner of the 911 S5 botnet (aka 911[.]re). — https://www.justice.gov/... “Since 2014, 911 S5 allegedly enabled cybercriminals to bypass financial fraud detection systems and steal billions of dollars from financial institutions, credit card issuers, and federal lending programs. … @briankrebs@infosec.exchange · BrianKrebs
Discussion
-
@europol
@europol
on x
🚨Largest ever operation against botnets hits dropper malware ecosystem. Operation Endgame, coordinated from Europol headquarters, has led to four arrests and the takedown of over 100 servers worldwide. More information in our press release⤵️ https://www.europol.europa.eu/ ...
-
@spamhaus
@spamhaus
on x
🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies👏👏 As with
-
@aejleslie
Alexander Leslie
on x
👀 🚨 “Operation Endgame...targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot.” Massive. Anxiously awaiting further details, but this initial news will reverberate throughout the cybercriminal underground. Unbelievable effort here.
-
@jeremy_kirk
Jeremy Kirk
on x
Huge cybercrime news here. Authorities say they've disrupted six types of botnets/loaders/cybercrime infrastructure: IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot https://www.europol.europa.eu/ ...
-
@rgb_lights
Rob Joyce
on x
Kudos to everyone involved in Operation Engame. It's a serious pushback against criminal capabilities that cause massive harm. Yes, there will be reconstitution in the future, but you can never stop challenging the bad actors in this space.
-
@ec3europol
@ec3europol
on x
🚨Largest ever operation against #botnets hits #dropper malware ecosystem. The result? 4 arrests and over 100 servers taken down worldwide! Europol's EC3 facilitated the information exchange and provided analytical, crypto-tracing and forensic support. https://twitter.com/...
-
@bitdefender
@bitdefender
on x
Bitdefender partners with Europol and global allies to dismantle major malware infrastructures like IcedID and SystemBC. We are proud to support the largest-ever botnet takedown, advancing the fight against cybercrime. https://www.europol.europa.eu/ ...
-
@cyb3rmonk
Mehmet Ergene
on x
This is huge! International operation shut down droppers including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee leading to four arrests and takedown of over 100 servers worldwide. #ThreatIntelligence #ThreatIntel https://www.europol.europa.eu/ ...
-
@profwoodward
Alan Woodward
on x
Botnets suffer serious blow as law enforcement agencies collaborate internationally to take down 100+ servers https://www.europol.europa.eu/ ...
-
@gi7w0rm
@gi7w0rm
on x
One of the biggest residential proxy botnets, which infected over 19 Mio unique IPs, has been seized by Law Enforcement. The main admin was arrested and the service taken down. This was probably one of the top 3 global proxy nets for comiting crimes of all sorts. Huge win 👌🥳
-
@bocbotch
@bocbotch
on x
@FBI Nice excuse for insider fraud?
-
@d4rkr4bb1t47
Pavel Kravchenko
on x
@TheJusticeDept Oh good, I'm still waiting for those child abuse websites in Miami, LV and New York to be dealt with.
-
@lynda555e
Lynda Edwards
on x
There are times the wheels of justice turn too slowly but busting this network of China's is impressive. It was involved in crimes from child exploitation to unemployment fraud
-
@imposecost
Andrew Thompson
on x
911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation A court-authorized international law enforcement operation led by the U.S. Justice Department disrupted a botnet used to commit cyber attacks, large-scale fraud, child exploitation,
-
@fbi
@fbi
on x
Today, the DOJ announced the arrest of a Chinese national who amassed millions of hijacked residential IP addresses and facilitated billions of dollars in unemployment and pandemic relief fraud. Learn about the investigation by the #FBI and its partners: https://www.justice.gov/.…
-
@statecdp
@statecdp
on x
The United States is designating three PRC nationals for activities associated with a malicious botnet known as 911 S5, which resulted in widespread cyber-enabled fraud and billions of dollars lost. Learn more: https://home.treasury.gov/...
-
@ariehkovler
Arieh Kovler
on x
Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022.
-
@statedeptspox
Matthew Miller
on x
The United States is sanctioning three PRC nationals associated with malicious cyber activity and three entities owned or controlled by one of them. We will continue to act against cybercriminals who seek to exploit our financial system.
-
@ariehkovler
Arieh Kovler
on x
Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022.
-
@frauhodl
@frauhodl
on x
I wonder why they called it “911 S5”-Botnet? - IXXI = 911 = Jesuits - YunHe Wang
-
@xhacknews
@xhacknews
on x
📡 #Botnet The 911 S5 botnet, which hijacked over 19 million IP addresses, has been dismantled in an international operation, and its administrator arrested. This was one of the top three proxy networks used globally for criminal activities. A major victory! #CyberSecurity
-
@chainalysis
@chainalysis
on x
Today, the DOJ announced the arrest of Yunhe Wang for his role as administrator of the 911 S5 botnet, one day after Wang was sanctioned by OFAC. Learn how investigators equipped with Chainalysis used cutting edge blockchain analysis techniques to analyze Wang's activities here.
-
@mrbcyber
Michael Ron Bowling
on x
Largest botnet ever taken down by FBI. The network was used for fraud, stalking, bomb threats and child exploitation. Note, this system would have been very useful for CCP foreign interference operations.
-
@fbidenver
@fbidenver
on x
#FBIDenver worked this case with @FBIDallas and many other partners, as listed in the DOJ news release https://twitter.com/...
-
@7trg6
@7trg6
on x
Let This Sink In - 911 S5 Botnet: Cyber Attacks, Fraud, Child Exploitation, Harassment, ID Theft 200 countries- 19 million IP addresses “...provided paying customers with access to proxied IP addresses associated with the infected devices” Ex: $5.9 billion unemployment (US)
-
@fbilasvegas
@fbilasvegas
on x
Protect against 911s5, a residential proxy service which compromised over 19 million IP addresses globally and caused billions of dollars in losses. Learn how the #FBI and partners disrupted the botnet to remove 911s5's applications from your devices #PSA https://www.ic3.gov/... …
-
@econmccausland
Hoa Paul Duong
on x
@StateDeptSpox Simple question. So is your job to lie blatantly to the international press and the American people?
-
@tayesuave
Tav
on x
@TheJusticeDept A Chinese national used Botnets and siphoned billions of dollars through multiple IP addresses. I wonder who all is connected with these crimes, its simply not a one-man operation.
-
@thejusticedept
@thejusticedept
on x
911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: https://www.justice.gov/... [video]
-
@780thc
@780thc
on x
Treasury Sanctions a Cybercrime Network Associated with the 911 S5 Botnet @USTreasury | https://home.treasury.gov/...
-
@itspawan_kumar
@itspawan_kumar
on x
The DOJ arrested YunHe Wang, a 35-year-old Chinese national, who was charged with operating the 911 S5 botnet. Wang faces a maximum of 65 years in prison if convicted on all counts, including conspiracy to commit computer fraud, wire fraud, and money laundering.
-
@blacklotuslabs
@blacklotuslabs
on x
Another bad day for botnet operators! Group behind CloudRouter and the old 911 S5 proxy botnets arrested! https://www.justice.gov/.... Our tracking of CloudRouter bot traffic shows interdiction was underway in early April #911s5 #botnet #infosec #crimeware #cloudburst [image]
-
@thejusticedept
@thejusticedept
on x
911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation; Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: [video]
-
@aejleslie
Alexander Leslie
on x
👀 🚨 “Today, [OFAC] designated three individuals, Yunhe Wang, Jingping Liu, and Yanni Zheng, for their activities associated with the malicious botnet tied to the residential proxy service known as 911 S5."https://home.treasury.gov/ ...