Europol, Eurojust, and others dismantle 1,025 servers used by the Rhadamanthys infostealer, VenomRAT, and Elysium botnet, in the latest Operation Endgame phase
Law enforcement authorities from nine countries have taken down over 1,000 servers used by the Rhadamanthys infolstealer …
It also extends a recent enforcement emphasis on infostealer infrastructure: an Interpol-led action had already disrupted infostealer operations across 26 countries. The significance is the scale and breadth of the server seizure across three named malware ecosystems.
First-order effects
The removal of 1,025 servers directly interrupts infrastructure used by Rhadamanthys, VenomRAT, and the Elysium botnet, limiting operators’ ability to run those systems through the seized servers.
Europol, Eurojust, and participating authorities gain operational disruption against the named criminal infrastructure rather than only against individual endpoints.
Second-order effects
Victims, security teams, and hosting or domain-service providers may get a near-term window to identify infections and block remaining infrastructure as affected operators re-establish services.
The action raises the operational cost for malware operators by forcing infrastructure replacement and making cross-border hosting arrangements more exposed to coordinated seizure.
Third-order effects
If repeated, coordinated server takedowns can shift cybercrime enforcement toward dismantling shared operational infrastructure, not solely prosecuting individual actors or cleaning infected machines.
The lasting effect remains uncertain: durable disruption depends on whether authorities can continue to identify replacement infrastructure as quickly as operators rebuild it.
The trend: This is one data point in the growing use of multinational, infrastructure-level enforcement to disrupt cybercrime services and the ecosystems that sustain them.
Operation Endgame's latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium. Read more in our press release: https://www.europol.europa.eu/ ... [image]
We had the privilege of spending time with many of the folks involved in the latest season of Operation Endgame while in The Hague this week. The agencies involved in these actions are extremely well organised and coordinated and whilst this is now the third round of Endgame
The U.S. and 10 other countries conducted a joint law-enforcement operation against a major infostealer, a remote access trojan, and a botnet, disrupting more than 1,000 servers and seizing 20 domains. The suspected lead operator of the RAT was also arrested. www.europol.europa.…
New from @europol.europa.eu: 1025 servers taken down; Operation Endgame's latest phase targeted the infostealer Rhadamanthys, Remote Access Trojan VenomRAT, and the botnet Elysium. www.europol.europa.eu/media-press/ ... #cybercrime #cybersecurity @gate15.bsky.social @campuscodi.r…
Proud to once again support our LE partners in Operation Endgame Season 3 — 86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12 — More details: — shadowserver.org/news…
It was Operation Endgame that took down Rhadamanthys. — End of the game for cybercrime infrastructure: 1025 servers taken down — www.europol.europa.eu/media-press/ ...