/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Europol, Eurojust, and others dismantle 1,025 servers used by the Rhadamanthys infostealer, VenomRAT, and Elysium botnet, in the latest Operation Endgame phase

Law enforcement authorities from nine countries have taken down over 1,000 servers used by the Rhadamanthys infolstealer …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is a further infrastructure-focused phase of Operation Endgame, following multinational actions against ransomware-distribution botnets and servers hosting abused Cobalt Strike installations.

It also extends a recent enforcement emphasis on infostealer infrastructure: an Interpol-led action had already disrupted infostealer operations across 26 countries. The significance is the scale and breadth of the server seizure across three named malware ecosystems.

First-order effects

  • The removal of 1,025 servers directly interrupts infrastructure used by Rhadamanthys, VenomRAT, and the Elysium botnet, limiting operators’ ability to run those systems through the seized servers.
  • Europol, Eurojust, and participating authorities gain operational disruption against the named criminal infrastructure rather than only against individual endpoints.

Second-order effects

  • Victims, security teams, and hosting or domain-service providers may get a near-term window to identify infections and block remaining infrastructure as affected operators re-establish services.
  • The action raises the operational cost for malware operators by forcing infrastructure replacement and making cross-border hosting arrangements more exposed to coordinated seizure.

Third-order effects

  • If repeated, coordinated server takedowns can shift cybercrime enforcement toward dismantling shared operational infrastructure, not solely prosecuting individual actors or cleaning infected machines.
  • The lasting effect remains uncertain: durable disruption depends on whether authorities can continue to identify replacement infrastructure as quickly as operators rebuild it.

The trend: This is one data point in the growing use of multinational, infrastructure-level enforcement to disrupt cybercrime services and the ecosystems that sustain them.

Discussion

  • @uk_daniel_card @uk_daniel_card on x
    “The main suspect for VenomRAT was also arrested in Greece on 3 November 2025.” @Europol https://www.europol.europa.eu/ ...
  • @pancak3lullz @pancak3lullz on x
    S03E01 - STICKY FINGERS https://operation-endgame.com/ ... https://www.europol.europa.eu/ ... #OpEndgame
  • @uk_daniel_card @uk_daniel_card on x
    Nice work @NCA_UK @Europol and all! [image]
  • @europol @europol on x
    Operation Endgame's latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium. Read more in our press release: https://www.europol.europa.eu/ ... [image]
  • @troyhunt Troy Hunt on x
    We had the privilege of spending time with many of the folks involved in the latest season of Operation Endgame while in The Hague this week. The agencies involved in these actions are extremely well organised and coordinated and whilst this is now the third round of Endgame
  • @ericjgeller.com Eric Geller on bluesky
    The U.S. and 10 other countries conducted a joint law-enforcement operation against a major infostealer, a remote access trojan, and a botnet, disrupting more than 1,000 servers and seizing 20 domains.  The suspected lead operator of the RAT was also arrested. www.europol.europa.…
  • @andyjabbour Andy Jabbour on bluesky
    New from @europol.europa.eu: 1025 servers taken down; Operation Endgame's latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium. www.europol.europa.eu/media-press/ ... #cybercrime #cybersecurity @gate15.bsky.social @campuscodi.r…
  • @shadowserver @shadowserver on bluesky
    Proud to once again support our LE partners in Operation Endgame Season 3  —  86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12  —  More details:  —  shadowserver.org/news…
  • @metacurity.com Cynthia Brumfield on bluesky
    It was Operation Endgame that took down Rhadamanthys.  —  End of the game for cybercrime infrastructure: 1025 servers taken down  —  www.europol.europa.eu/media-press/ ...