/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Europol says police in Germany, the UK, the US, and others took down botnets spreading ransomware via infected emails, arrested four, and seized 2,000+ domains

Police coordinated by the European Union's justice and police agencies have taken down computer networks responsible …

Associated Press Mike Corder

Context & Ripple Effects

The operation extends a recurring Europol-led model: cross-border agencies target both ransomware operators and the infrastructure that delivers or supports their campaigns. A prior seizure of Emotet's infrastructure showed the same emphasis on disrupting malware operations from inside their technical footprint.

It also follows the disruption of a DoppelPaymer-linked ransomware gang, reinforcing that international cases increasingly combine technical takedowns with arrests rather than treating them as separate actions.

First-order effects

  • The seized domains and dismantled botnets immediately remove identified email-based ransomware delivery infrastructure from the operators' control.
  • Four arrests give investigators potential access to operational evidence and disrupt the people tied to the campaign, while affected organizations gain a break from the identified distribution network.

Second-order effects

  • Operators behind the campaign must replace domains and rebuild delivery infrastructure before they can resume a comparable email-based operation, raising the operational cost of the campaign.
  • Security teams can use indicators associated with the seized infrastructure to hunt for prior exposure and tighten email controls, though a takedown does not by itself remove infections already present on endpoints.

Third-order effects

  • If these coordinated seizures continue, ransomware enforcement will increasingly depend on denying criminals access to the domains and botnet infrastructure that make campaigns scalable, alongside pursuing individual suspects.
  • The pattern may favor more durable international coordination: operators can relocate, but infrastructure and evidence often span jurisdictions, making unilateral enforcement less effective.

The trend: Ransomware enforcement is shifting toward coordinated disruption of the technical delivery layer as well as arrests of the people operating it.

Discussion

  • @europol @europol on x
    🚨Largest ever operation against botnets hits dropper malware ecosystem. Operation Endgame, coordinated from Europol headquarters, has led to four arrests and the takedown of over 100 servers worldwide. More information in our press release⤵️ https://www.europol.europa.eu/ ...
  • @spamhaus @spamhaus on x
    🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies👏👏 As with
  • @aejleslie Alexander Leslie on x
    👀 🚨 “Operation Endgame...targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot.” Massive. Anxiously awaiting further details, but this initial news will reverberate throughout the cybercriminal underground. Unbelievable effort here.
  • @jeremy_kirk Jeremy Kirk on x
    Huge cybercrime news here. Authorities say they've disrupted six types of botnets/loaders/cybercrime infrastructure: IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot https://www.europol.europa.eu/ ...
  • @rgb_lights Rob Joyce on x
    Kudos to everyone involved in Operation Engame. It's a serious pushback against criminal capabilities that cause massive harm. Yes, there will be reconstitution in the future, but you can never stop challenging the bad actors in this space.
  • @ec3europol @ec3europol on x
    🚨Largest ever operation against #botnets hits #dropper malware ecosystem. The result? 4 arrests and over 100 servers taken down worldwide! Europol's EC3 facilitated the information exchange and provided analytical, crypto-tracing and forensic support. https://twitter.com/...
  • @bitdefender @bitdefender on x
    Bitdefender partners with Europol and global allies to dismantle major malware infrastructures like IcedID and SystemBC. We are proud to support the largest-ever botnet takedown, advancing the fight against cybercrime. https://www.europol.europa.eu/ ...
  • @cyb3rmonk Mehmet Ergene on x
    This is huge! International operation shut down droppers including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee leading to four arrests and takedown of over 100 servers worldwide. #ThreatIntelligence #ThreatIntel https://www.europol.europa.eu/ ...
  • @profwoodward Alan Woodward on x
    Botnets suffer serious blow as law enforcement agencies collaborate internationally to take down 100+ servers https://www.europol.europa.eu/ ...
  • @gi7w0rm @gi7w0rm on x
    One of the biggest residential proxy botnets, which infected over 19 Mio unique IPs, has been seized by Law Enforcement. The main admin was arrested and the service taken down. This was probably one of the top 3 global proxy nets for comiting crimes of all sorts. Huge win 👌🥳
  • @bocbotch @bocbotch on x
    @FBI Nice excuse for insider fraud?
  • @d4rkr4bb1t47 Pavel Kravchenko on x
    @TheJusticeDept Oh good, I'm still waiting for those child abuse websites in Miami, LV and New York to be dealt with.
  • @lynda555e Lynda Edwards on x
    There are times the wheels of justice turn too slowly but busting this network of China's is impressive. It was involved in crimes from child exploitation to unemployment fraud
  • @imposecost Andrew Thompson on x
    911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation A court-authorized international law enforcement operation led by the U.S. Justice Department disrupted a botnet used to commit cyber attacks, large-scale fraud, child exploitation,
  • @fbi @fbi on x
    Today, the DOJ announced the arrest of a Chinese national who amassed millions of hijacked residential IP addresses and facilitated billions of dollars in unemployment and pandemic relief fraud. Learn about the investigation by the #FBI and its partners: https://www.justice.gov/.…
  • @statecdp @statecdp on x
    The United States is designating three PRC nationals for activities associated with a malicious botnet known as 911 S5, which resulted in widespread cyber-enabled fraud and billions of dollars lost. Learn more: https://home.treasury.gov/...
  • @ariehkovler Arieh Kovler on x
    Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022.
  • @statedeptspox Matthew Miller on x
    The United States is sanctioning three PRC nationals associated with malicious cyber activity and three entities owned or controlled by one of them. We will continue to act against cybercriminals who seek to exploit our financial system.
  • @ariehkovler Arieh Kovler on x
    Quite the scalp for @briankrebs who exposed Yunhe Wang as one of the creators of this network back in 2022.
  • @frauhodl @frauhodl on x
    I wonder why they called it “911 S5”-Botnet? - IXXI = 911 = Jesuits - YunHe Wang
  • @xhacknews @xhacknews on x
    📡 #Botnet The 911 S5 botnet, which hijacked over 19 million IP addresses, has been dismantled in an international operation, and its administrator arrested. This was one of the top three proxy networks used globally for criminal activities. A major victory! #CyberSecurity
  • @chainalysis @chainalysis on x
    Today, the DOJ announced the arrest of Yunhe Wang for his role as administrator of the 911 S5 botnet, one day after Wang was sanctioned by OFAC. Learn how investigators equipped with Chainalysis used cutting edge blockchain analysis techniques to analyze Wang's activities here.
  • @mrbcyber Michael Ron Bowling on x
    Largest botnet ever taken down by FBI. The network was used for fraud, stalking, bomb threats and child exploitation. Note, this system would have been very useful for CCP foreign interference operations.
  • @fbidenver @fbidenver on x
    #FBIDenver worked this case with @FBIDallas and many other partners, as listed in the DOJ news release https://twitter.com/...
  • @7trg6 @7trg6 on x
    Let This Sink In - 911 S5 Botnet: Cyber Attacks, Fraud, Child Exploitation, Harassment, ID Theft 200 countries- 19 million IP addresses “...provided paying customers with access to proxied IP addresses associated with the infected devices” Ex: $5.9 billion unemployment (US)
  • @fbilasvegas @fbilasvegas on x
    Protect against 911s5, a residential proxy service which compromised over 19 million IP addresses globally and caused billions of dollars in losses. Learn how the #FBI and partners disrupted the botnet to remove 911s5's applications from your devices #PSA https://www.ic3.gov/... …
  • @econmccausland Hoa Paul Duong on x
    @StateDeptSpox Simple question. So is your job to lie blatantly to the international press and the American people?
  • @tayesuave Tav on x
    @TheJusticeDept A Chinese national used Botnets and siphoned billions of dollars through multiple IP addresses. I wonder who all is connected with these crimes, its simply not a one-man operation.
  • @thejusticedept @thejusticedept on x
    911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: https://www.justice.gov/... [video]
  • @780thc @780thc on x
    Treasury Sanctions a Cybercrime Network Associated with the 911 S5 Botnet @USTreasury | https://home.treasury.gov/...
  • @itspawan_kumar @itspawan_kumar on x
    The DOJ arrested YunHe Wang, a 35-year-old Chinese national, who was charged with operating the 911 S5 botnet. Wang faces a maximum of 65 years in prison if convicted on all counts, including conspiracy to commit computer fraud, wire fraud, and money laundering.
  • @blacklotuslabs @blacklotuslabs on x
    Another bad day for botnet operators! Group behind CloudRouter and the old 911 S5 proxy botnets arrested! https://www.justice.gov/.... Our tracking of CloudRouter bot traffic shows interdiction was underway in early April #911s5 #botnet #infosec #crimeware #cloudburst [image]
  • @thejusticedept @thejusticedept on x
    911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation; Botnet Infected Over 19M IP Addresses to Enable Billions of Dollars in Pandemic and Unemployment Fraud, and Access to Child Exploitation Materials 🔗: [video]
  • @aejleslie Alexander Leslie on x
    👀 🚨 “Today, [OFAC] designated three individuals, Yunhe Wang, Jingping Liu, and Yanni Zheng, for their activities associated with the malicious botnet tied to the residential proxy service known as 911 S5."https://home.treasury.gov/ ...